Gallery

Contacts

405 W. Greenlawn Ave Lansing, Michigan 48910

contact@techjacksolutions.com

+1-616-320-4064

Unknown threat actors compromised ShapedPlugin’s software build and distribution pipeline, injecting backdoor code into three paid WordPress plugins delivered through the vendor’s own licensed update system. Any WordPress site that updated Product Slider Pro for WooCommerce (before 3.5.4), Real Testimonials Pro (3.2.5), or Smart Post Show Pro (before 4.0.2) through official channels may have received a backdoored version capable of stealing credentials, exfiltrating database configuration secrets, deploying web shells, and bypassing two-factor authentication. The attack targets paying customers who followed best practices by updating through an authenticated vendor channel, making standard update-trust assumptions unreliable for this vendor until the pipeline is confirmed clean.

Author

Tech Jacks Solutions