← Back to feed
vendor Wordfence Blog

PSA: Supply Chain Compromise Targets ShapedPlugin, Backdoored Pro Plugins Distributed via Official Channels

Wordfence Blog Intel

The Wordfence Threat Intelligence Team was notified on June 11th, 2026 of a potential supply chain compromise affecting ShapedPlugin, a WordPress plugin vend...

T1195
Read the full story Wordfence Blog →

Related Coverage

vendor PSA: Critical Unauthenticated Path Traversal Vulnerability Patched in WordPress Core Wordfence Blog · Sep 22 vendor Unmasking EvilTokens: Getting to the root of device code phishing Microsoft Security Blog · Sep 22 vendor Inside a Malicious, Stealthy WordPress Must Use Plugin Wordfence Blog · Sep 22