CYBERSECURITYTRACKER
TRACKING6,506 stories in this site build1,309 vulnerability news stories in this site build
Permanent story citation

Supply Chain Compromise: Trojanized Copy of WowShipping Pro Installs Hidden Remote Access Toolkit

This page keeps the story as Cybersecurity Tracker first published it. If the tracker later corrects it, the correction appears below the original and never replaces it.

Back to newsStory 6283

As cited

Copy frozen at (site build).

vulnerabilities

Supply Chain Compromise: Trojanized Copy of WowShipping Pro Installs Hidden Remote Access Toolkit

WPXPO's WowShipping Pro WordPress plugin was compromised in its supply chain, with trojanized versions of v1.0.6 containing a dropper that installs a feature-complete malware plugin masquerading as WooCommerce Notifications. The malware captures login credentials and TOTP secrets, provides authentication bypass and remote code execution, and includes bundled database and file manager access tools. WPXPO released clean versions v1.0.7 and v1.0.8 on March 22, 2026, but the vendor's customer notification lacked remediation details and did not disclose that the malware persists independently after updating.

Why it matters: WooCommerce store owners running WowShipping Pro must verify that the woocommerce-notifications plugin directory does not exist on their sites, rotate all administrator passwords and 2FA secrets, invalidate sessions, and review logs for database or file manager access, since the malware exfiltrates credentials and 2FA secrets that bypass multifactor authentication.

Source published
First seen by Cybersecurity Tracker

Source attribution

Correction

Correction recorded as of .

vulnerabilities

Supply Chain Compromise: Trojanized Copy of WowShipping Pro Installs Hidden Remote Access Toolkit

WPXPO's WowShipping Pro WordPress plugin was compromised in its supply chain, with trojanized versions of v1.0.6 containing a dropper that installs a feature-complete malware plugin masquerading as WooCommerce Notifications. The malware captures login credentials and TOTP secrets, provides authentication bypass and remote code execution, and includes bundled database and file manager access tools. WPXPO released clean versions v1.0.7 and v1.0.8 on March 22, 2026, but the vendor's customer notification lacked remediation details and did not disclose that the malware persists independently after updating.

Why it matters: WooCommerce store owners running WowShipping Pro must verify that the woocommerce-notifications plugin directory does not exist on their sites, rotate all administrator passwords and 2FA secrets, invalidate sessions, and review logs for database or file manager access, since the malware exfiltrates credentials and 2FA secrets that bypass multifactor authentication.

VendorsAdobeWordPress
Source published
First seen by Cybersecurity Tracker

Source attribution

Glossary