HackerFeeds

CyberSecurity News

ShapedPlugin WordPress Pro Plugins Backdoored in Supply Chain Attack

The Hacker News
· June 22, 2026

AI summary

A supply chain attack has compromised multiple WordPress plugins from ShapedPlugin, allowing unknown threat actors to inject backdoor code into official releases. The attackers were able to tamper with the vendor's build and distribution pipeline, enabling them to push the backdoored code through licensed update channels. This means that the compromised plugins were distributed through official channels, potentially affecting users who updated their plugins through legitimate means. Wordfence has conducted an analysis of the incident, detailing the extent of the compromise. The attack highlights a vulnerability in the plugin development and distribution process. Users of the affected ShapedPlugin plugins may be at risk due to the backdoor code.

Read the full article at The Hacker Newsthehackernews.com/2026/06/shapedplugin-wordpress-pro-plugins.html

This is an AI-generated brief aggregated by HackerFeeds for convenience and grounded in the source’s own summary; the related CVE, threat-group and country data is from HackerFeeds’ own indexes. The original article is the authoritative source — all rights belong to The Hacker News.