Skip to content
CVSS 10.0CVSS 10.0 · CRITICAL

CVE-2026-49777

Improper Validation of Specified Quantity in Input vulnerability in ShapedPlugin, LLC Product Slider Pro for WooCommerce allows Malicious Software Implanted. This issue affects Product Slider Pro for WooCommerce: from n/a before 3.5.4.

View on NVD

Analysis

El plugin Product Slider Pro para WooCommerce permite la implantación de software malicioso debido a una validación de entrada incorrecta, alcanzando la severidad máxima de 10.0. Dado que el desarrollador aplicó el parche sobre la versión 3.5.3 existente sin incrementar el número de versión, los usuarios deben reinstalar el plugin manualmente para asegurar que su instalación no sea vulnerable. Esta falla crítica permite a un atacante comprometer totalmente el servidor de WordPress afectado.

Relevant roles

PhpBackendCyberSecurity

Severity

Score: 10.0(CRITICAL)
Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
AV: NETWORK
AC: LOW
PR: NONE
UI: NONE
S: CHANGED
C: HIGH
I: HIGH
A: HIGH
Weakness (CWE): CWE-1284

EPSS

Probability of exploitation (next 30 days): 0.0006 (0.1%)
Percentile: 19.8%
EPSS: 2026-06-08

Technical description

Improper Validation of Specified Quantity in Input vulnerability in ShapedPlugin, LLC Product Slider Pro for WooCommerce allows Malicious Software Implanted. This issue affects Product Slider Pro for WooCommerce: from n/a before 3.5.4.

Published: 6/5/2026, 9:16:26 AM
Last modified: 6/8/2026, 5:16:52 PM

References

HomeEventsBlogResourcesTeam