WowShipping Pro 1.0.6 - Injected Backdoor
criticalThe WowShipping Pro plugin for WordPress was injected with a backdoor in version 1.0.6. This is due to a supply chain compromise where an attacker was able to infect the copy of the plugin from the source. This makes it possible for attackers to remotely access victim WordPress instances completely infect the victim.
- CVSS:
- 9.8
- Affected:
- up to 1.0.8
- Fixed in:
- 1.0.8
- Disclosed:
- Apr 17, 2026