
ShapedPlugin WordPress Pro Plugins Backdoored in Supply Chain Breach
A supply chain attack has injected backdoors into ShapedPlugin’s premium WordPress plugins, putting thousands of sites at risk. Immediate action is needed to detect and remove the malicious code.
A significant supply chain compromise has struck ShapedPlugin, a known provider of professional WordPress plugins. Attackers managed to infiltrate the distribution channel for the company’s Pro (premium) plugins, inserting a backdoor into the code before it reached customers. The tainted versions, once installed on a website, grant unauthorized remote access to the attacker, potentially allowing full site takeover, data theft, or further malware deployment.
Supply chain attacks of this nature are particularly dangerous because the malicious code arrives through what appears to be a legitimate update or download from a trusted source. In this case, the backdoor was embedded directly into the plugin files distributed via ShapedPlugin’s own infrastructure, meaning sites that applied updates or newly installed the Pro plugins during the affected window are likely compromised. Early indicators suggest the backdoor can execute arbitrary PHP code, create hidden admin users, and maintain persistence even after the plugin is disabled.
For website owners and administrators, the immediate priority is to audit any ShapedPlugin Pro installations. Check for unexpected files, especially in plugin directories, and compare file checksums against known clean versions. Review user accounts for unauthorized administrators, and scan the site with a reputable security tool. If a compromise is confirmed, restoring from a clean backup prior to the attack and updating to a verified clean version of the plugin is essential. Additionally, rotating all associated credentials, including database and hosting passwords, is strongly advised.
This incident underscores the critical role of defense-in-depth strategies for WordPress hosting environments. Managed WordPress hosting services, such as AEU Hosting, often provide automated malware scanning, virtual patching, and controlled update rollouts that can reduce the exposure window by detecting unusual behavior or blocking known compromised versions before they are widely installed. While no solution is foolproof, leveraging such layered protections can significantly lower the risk posed by supply chain threats.