Briefing

ShapedPlugin Supply‑Chain Attack Injects Backdoor into Pro Plugins

security
by [email protected] (The Hacker News) · WordPress Wordfence

Notify users of ShapedPlugin and roll back to a clean version before the compromised release.

What to do now

Notify users of ShapedPlugin and roll back to a clean version before the compromised release.

Summary

Multiple WordPress plugins from ShapedPlugin were compromised in a supply chain attack after unknown threat actors managed to tamper with the official release channels and push backdoor code. Attackers compromised the vendor's build and distribution pipeline, injecting backdoor code into Pro plugin releases distributed through official licensed update channels, Wordfence said in an analysis.

The compromised plugins include ShapedPlugin's Pro suite, which offers advanced layout and design features for WordPress sites. The backdoor code allows attackers to execute arbitrary PHP code, exfiltrate data, and maintain persistence on affected sites. Wordfence recommends that site owners immediately remove the compromised plugins and revert to a clean version from a trusted source. The incident underscores the importance of verifying plugin integrity and monitoring for unauthorized changes in the update process. Users should also enable automatic updates and keep backups to mitigate potential damage.

Key changes

  • Supply chain attack on ShapedPlugin
  • Backdoor code injected into Pro plugin releases
  • Compromised build and distribution pipeline
  • Backdoor allows arbitrary PHP execution
  • Exfiltration of data
  • Wordfence analysis
  • Affected sites must remove plugins
  • Importance of verifying plugin integrity

Affects

wp-customers

Customer impact

Analyzing matches…

Ask about this story

Impact on an agency? Which customers? Compare historically Risks of waiting