CVE-2026-10735 tracks a supply-chain compromise affecting multiple premium ShapedPlugin WordPress plugins distributed through the vendor’s official update infrastructure. Affected products include Smart Post Show Pro before 4.0.2, Real Testimonials Pro before 3.2.5, and Product Slider for WooCommerce Pro before 3.5.3/3.5.4 according to the provided reporting. The compromised releases contained malicious code inserted into the vendor’s build or distribution pipeline rather than the public WordPress.org repository. The injected loader, reported as LicenseLoader.php in some analyses, executed on WordPress admin page loads, contacted attacker-controlled infrastructure at 194.76.217.28:2871, downloaded a second-stage payload, installed it as a fake hidden plugin such as woocommerce-subscription or woocommerce-notification, reported the victim back to the attacker, and then self-deleted to reduce forensic visibility. The second stage established persistence and exposed extensive site data, including WordPress credentials, 2FA codes or secrets, wp-config.php contents, administrator account details, SMTP credentials, and WooCommerce order data. Reporting also states the malware enabled arbitrary file writes through a custom REST endpoint and could deploy web-shell-like functionality, resulting in full compromise of affected sites.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
1 valid exploit after Mallory filtered fakes, detection scripts, and README-only repos (1 hidden).
Repository contains a single Python exploit script and a minimal README. The main file, CVE-2026-49777.py, is a standalone interactive exploitation tool targeting an alleged ShapedPlugin supply-chain compromise / LicenseLoader RCE affecting WordPress plugin deployments. The script is not part of a known exploitation framework. Structurally, the script includes: banner/UI code; logging helpers; result persistence to pwned.txt; IOC detection logic; login-bypass logic using a hardcoded MD5 value; RCE-related constants including a WooCommerce-style REST path (/wp-json/wc/v3/settings/apply), a command parameter key (wc_diag), and a header artifact (X-Cache-Status); single-target exploitation flow; and multithreaded bulk scanning from a user-supplied target list. The visible code shows the exploit first probing targets for compromise indicators by requesting fake plugin directories and specific PHP files under /wp-content/plugins/. It also checks the site root for an X-Cache-Status header whose 8-character alphanumeric value is treated as confirmation of header-based RCE behavior. The script then attempts a login bypass against an admin username using a hardcoded MD5 hash and proceeds toward command execution with an operator-supplied command, defaulting to id. Successful targets are recorded in pwned.txt. Overall purpose: this is an operational exploit/scanner for compromised WordPress sites, combining detection and exploitation. It supports both validation of infection/backdoor artifacts and active post-compromise command execution across one or many targets.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
8 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A high-severity CVE assigned to the broader ShapedPlugin WordPress plugin supply chain compromise incident involving tampered official release channels and backdoored Pro plugin updates.
A supply-chain compromise affecting ShapedPlugin paid WordPress plugins, where infected official updates delivered a malicious loader and backdoor that installed fake WooCommerce plugins, stole credentials and secrets, and enabled remote file-writing capabilities.
A critical supply-chain backdoor compromise affecting premium ShapedPlugin WordPress plugin releases distributed through official channels.
A supply-chain backdoor affecting multiple ShapedPlugin Pro WordPress plugins, delivered via a compromised vendor update server. The malicious updates allowed unauthenticated attackers to deploy a second-stage payload, exfiltrate credentials and sensitive data, and gain full control of affected sites.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.