WordPress Product Slider Pro for WooCommerce plugin < 3.5.4 - Backdoor vulnerability
85Vexday Risk Score
Patch now. It exploitation observed by VulnCheck and has a working public exploit.
ssvc Actcvss 10epss 1.7%
from disclosure to weapon7 days
Published on NVDJun 5
1st PoC+7d
VulnCheckJun 5
exploitation probability
1.7%top 26% of all CVEs
observed exploitation
yesVulnCheck
5 public exploit(s)
In short
The WordPress Product Slider Pro for WooCommerce plugin (versions before 3.5.4) has a critical vulnerability that allows attackers to implant malicious software into websites. The plugin fails to properly validate user input, giving attackers a way to compromise the entire site.
Technical detail
CWE-1284 (improper validation of specified quantity in input) enables remote code injection through insufficiently validated input parameters. The vulnerability allows unauthenticated or low-privileged attackers to implant malicious software without proper authorization checks, resulting in complete site compromise. Affected versions: Product Slider Pro for WooCommerce < 3.5.4.
Summary generated and translated by AI from the official description.
Improper Validation of Specified Quantity in Input vulnerability in ShapedPlugin, LLC Product Slider Pro for WooCommerce allows Malicious Software Implanted.
This issue affects Product Slider Pro for WooCommerce: from n/a before 3.5.4.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
Affected products
ShapedPlugin, LLC · Product Slider Pro for WooCommercepublic PoCs found — 5
githubgithub.com/amnsecurity/CVE-2026-49777-WooCommerce-RCE★ 1githubgithub.com/izxci/CVE-2026-49777★ 0githubgithub.com/xxconi/CVE-2026-49777-CVE-2026-10735★ 0githubgithub.com/HORKimhab/CVE-Wordpress★ 0vulncheckvulncheck.com/xdb/bd2b913d6d3dunverified⚠ Public resources, to assess the exposure of systems you control or are authorized to test. Test only with authorization.