Attackers injected backdoors into three ShapedPlugin premium WordPress plugins on May 21, 2026, using the official update system to steal credentials and install hidden fake WooCommerce plugins on customer sites.

Each tainted package included a loader called LicenseLoader.php.
Wordfence has advised administrators to treat any premium installations from April through June 2026 as potentially compromised.
WordPress site owners should treat all premium ShapedPlugin installs from April through June 2026 as potentially compromised and audit for fake WooCommerce plugins immediately.
Tap a lens to see what this story means for you.
Reader-supported · Daily Brief
Daily brief at 7 AM ET. Top tech stories, every morning. Sourced and fact-checked.
Reader-supported
The Circuitry is a passion project I've always wanted to build, and I love the work behind it.
Running it costs real money. APIs, hosting, time. To keep improving the site and growing this into something useful for everyone, those costs have to be covered.
Any contribution is appreciated. If not, no pressure. Thanks for reading.
Some Pixel users cannot get the keyboard to appear when replying to emails in the Gmail app despite visible AI suggestions. The bug emerged in the last 24 hours on Pixel devices only and Google has not yet acknowledged it.
Apple has introduced iOS modifications in Brazil that open authorized alternative marketplaces and external payment tools under a CADE agreement while adding Notarization plus child-safety rules. The steps target newly created malware, fraud, and privacy hazards on the platform Apple still calls the most secure mobile option locally.
F5 released out-of-band patches for two critical NGINX vulnerabilities that can lead to remote code execution or denial-of-service on non-default setups. The updates also fix high-severity configuration injection issues in NGINX Gateway Fabric against a backdrop of frequent real-world targeting of F5 products.