CVE-2026-10735 records a compromise of ShapedPlugin's update server that distributed malicious code through Smart Post Show Pro, Real Testimonials Pro, and Product Slider for WooCommerce Pro. The malicious update can exfiltrate credentials and enable site control. Because this is a supply-chain incident, updating alone is insufficient; affected sites need credential rotation and compromise assessment.
Vulnerability Overview and Scope of Impact
Fixed floors in CVE-2026-10735 are Smart Post Show Pro 4.0.2, Real Testimonials Pro 3.2.5, and Product Slider for WooCommerce Pro 3.5.3. A separate record, CVE-2026-49777, covers Product Slider Pro for WooCommerce before 3.5.4 and is rated CVSS v3.1 10.0 CRITICAL by Patchstack. Updating that product to 3.5.4 or later resolves both stated floors.
WPScan's CNA rates CVE-2026-10735 CVSS v3.1 7.5 HIGH. This is separate from Patchstack's 10.0 assessment of CVE-2026-49777 for Product Slider Pro. The records cover different scopes; the lower score does not remove the need to investigate credential exposure and compromise.
Responding to suspected compromise
Reinstall fixed packages from a trusted distribution channel. Rotate WordPress administrator, hosting, SFTP/SSH, database, and API credentials. Inspect added administrators, mu-plugins, themes, scheduled tasks, web-root changes, and outbound connections. If compromise is found, restore from a known-good backup rather than trusting only the plugin update.
📦