< Back to all clusters
[TECHNOLOGY] · 2 sources

WordPress plugins face severe backdoor supply‑chain attack and active SMTP data‑leak exploit

ShapedPlugin confirmed a supply‑chain breach on June 22, 2026 that inserted a backdoor into the Pro versions of three of its premium WordPress plugins – Product Slider Pro for WooCommerce, Real Testimonials Pro and Smart Post Show Pro. The malicious code steals administrator passwords, two‑factor authentication codes and e‑commerce data before deleting itself, and has been assigned CVE‑2026‑49777 with a maximum CVSS score of 10. Only customers who purchased the paid extensions directly from the vendor were affected; the free versions on WordPress.org remain safe. ShapedPlugin is issuing validated security updates and advises site owners to reset credentials.

A separate vulnerability, CVE‑2026‑4020, in the Gravity SMTP WordPress plugin is being actively exploited. The flaw exposes system information, API keys, OAuth tokens, plugin inventories and server configuration through an unauthenticated REST endpoint. Although it does not enable remote code execution, the disclosed data facilitates credential theft and further attacks. Security experts recommend updating to version 2.1.5 or discontinuing the plugin. The issue has a CVSS score of 5.3 but is considered high‑impact due to active exploitation.