As cited
Copy frozen at (site build).
vulnerabilities
Supply Chain Compromise: Trojanized Copy of WowShipping Pro Installs Hidden Remote Access Toolkit
WPXPO's WowShipping Pro WordPress plugin was compromised in its supply chain, with trojanized versions of v1.0.6 containing a dropper that installs a feature-complete malware plugin masquerading as WooCommerce Notifications. The malware captures login credentials and TOTP secrets, provides authentication bypass and remote code execution, and includes bundled database and file manager access tools. WPXPO released clean versions v1.0.7 and v1.0.8 on March 22, 2026, but the vendor's customer notification lacked remediation details and did not disclose that the malware persists independently after updating.
Why it matters: WooCommerce store owners running WowShipping Pro must verify that the woocommerce-notifications plugin directory does not exist on their sites, rotate all administrator passwords and 2FA secrets, invalidate sessions, and review logs for database or file manager access, since the malware exfiltrates credentials and 2FA secrets that bypass multifactor authentication.
- Source published
- First seen by Cybersecurity Tracker
Source attribution
Correction
Correction recorded as of .
vulnerabilities
Supply Chain Compromise: Trojanized Copy of WowShipping Pro Installs Hidden Remote Access Toolkit
WPXPO's WowShipping Pro WordPress plugin was compromised in its supply chain, with trojanized versions of v1.0.6 containing a dropper that installs a feature-complete malware plugin masquerading as WooCommerce Notifications. The malware captures login credentials and TOTP secrets, provides authentication bypass and remote code execution, and includes bundled database and file manager access tools. WPXPO released clean versions v1.0.7 and v1.0.8 on March 22, 2026, but the vendor's customer notification lacked remediation details and did not disclose that the malware persists independently after updating.
Why it matters: WooCommerce store owners running WowShipping Pro must verify that the woocommerce-notifications plugin directory does not exist on their sites, rotate all administrator passwords and 2FA secrets, invalidate sessions, and review logs for database or file manager access, since the malware exfiltrates credentials and 2FA secrets that bypass multifactor authentication.
- Source published
- First seen by Cybersecurity Tracker