FORSMILE
JA
セキュリティ2026/06/23

[URGENT] ShapedPlugin Supply-Chain Compromise: Verify Fixed Releases for Three Products — CVE-2026-10735/49777

A compromised update server distributed malicious code to three Pro plugins. Install each product's fixed release, rotate credentials, and investigate the site for persistence.

Back to Blog

CVE-2026-10735 records a compromise of ShapedPlugin's update server that distributed malicious code through Smart Post Show Pro, Real Testimonials Pro, and Product Slider for WooCommerce Pro. The malicious update can exfiltrate credentials and enable site control. Because this is a supply-chain incident, updating alone is insufficient; affected sites need credential rotation and compromise assessment.

Vulnerability Overview and Scope of Impact

Fixed floors in CVE-2026-10735 are Smart Post Show Pro 4.0.2, Real Testimonials Pro 3.2.5, and Product Slider for WooCommerce Pro 3.5.3. A separate record, CVE-2026-49777, covers Product Slider Pro for WooCommerce before 3.5.4 and is rated CVSS v3.1 10.0 CRITICAL by Patchstack. Updating that product to 3.5.4 or later resolves both stated floors.

⚠ CVE Score — 最高危険度 / CRITICAL
10CRITICALCVSS v3.1CVE-2026-49777
⚠ CVE Score — 高危険度 / HIGH
7.5HIGHCVSS v3.1CVE-2026-10735

WPScan's CNA rates CVE-2026-10735 CVSS v3.1 7.5 HIGH. This is separate from Patchstack's 10.0 assessment of CVE-2026-49777 for Product Slider Pro. The records cover different scopes; the lower score does not remove the need to investigate credential exposure and compromise.

Responding to suspected compromise

Reinstall fixed packages from a trusted distribution channel. Rotate WordPress administrator, hosting, SFTP/SSH, database, and API credentials. Inspect added administrators, mu-plugins, themes, scheduled tasks, web-root changes, and outbound connections. If compromise is found, restore from a known-good backup rather than trusting only the plugin update.

📦
Search Amazon US for related books and tools
cybersecurity server security tools
Search Amazon US → (affiliate link). As an Amazon Associate, we earn from qualifying purchases.

Reference Sources / Official Patch Information

Related articles