CVE-2026-10735: ShapedPlugin Multiple Pro Plugins - Backdoor via Compromised Vendor Update Server
Multiple Shapedsmart-post-show-pro WordPress plugin before 4.0.2, Real Testimonials Pro WordPress plugin before 3.2.5, Product Slider for WooCommerce Pro WordPress plugin before 3.5.3 Pro smart-post-show-pro WordPress plugin before 4.0.2, Real Testimonials Pro WordPress plugin before 3.2.5, Product Slider for WooCommerce Pro WordPress plugin before 3.5.3 were distributed with malicious code through the vendor's compromised update server, allowing unauthenticated attackers to deploy a second-stage payload that exfiltrates credentials and other sensitive data and grants full control of affected sites.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-10735?
The severity of CVE-2026-10735 is high, with a CVSS score of 7.5.
What vulnerability does CVE-2026-10735 describe?
CVE-2026-10735 describes a backdoor vulnerability in multiple ShapedPlugin WordPress plugins due to a compromised vendor update server.
How do I fix CVE-2026-10735?
To fix CVE-2026-10735, update all affected ShapedPlugin plugins to their latest versions as specified by the vendor.
Which plugins are affected by CVE-2026-10735?
CVE-2026-10735 affects ShapedPlugin Smart Post Show Pro, Real Testimonials Pro, and Product Slider for WooCommerce Pro plugins.
What is the potential impact of CVE-2026-10735?
The potential impact of CVE-2026-10735 includes unauthorized access and control over affected WordPress sites.