ShapedPlugin update flow hacked to infect WordPress sites
…Also, releases hosted on WordPress.org were confirmed to be clean, suggesting that the attackers gained access to ShapedPlugin’s release infrastructure. WordPress is currently tracking the incident under CVE-2026-10735…