Skip to content
CVSS 10.0CVSS 10.0 · CRITICAL

CVE-2026-49777

Improper Validation of Specified Quantity in Input vulnerability in ShapedPlugin, LLC Product Slider Pro for WooCommerce allows Malicious Software Implanted. This issue affects Product Slider Pro for WooCommerce: from n/a before 3.5.3. No patched version is available - the vendor has applied a fix to an existing release without publishing a new version. While the patch provided by the vendor is valid, releasing it under the existing version number leaves users unable to reliably determine whether they are running a patched or vulnerable installation. As a result, we treat this as an unpatched version.

View on NVD

Analysis

El plugin Product Slider Pro para WooCommerce permite la implantación de software malicioso debido a una validación de entrada incorrecta, alcanzando la severidad máxima de 10.0. Dado que el desarrollador aplicó el parche sobre la versión 3.5.3 existente sin incrementar el número de versión, los usuarios deben reinstalar el plugin manualmente para asegurar que su instalación no sea vulnerable. Esta falla crítica permite a un atacante comprometer totalmente el servidor de WordPress afectado.

Relevant roles

PhpBackendCyberSecurity

Severity

Score: 10.0(CRITICAL)
Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
AV: NETWORK
AC: LOW
PR: NONE
UI: NONE
S: CHANGED
C: HIGH
I: HIGH
A: HIGH
Weakness (CWE): CWE-1284

EPSS

Probability of exploitation (next 30 days): 0.0006 (0.1%)
Percentile: 20.0%
EPSS: 2026-06-05

Technical description

Improper Validation of Specified Quantity in Input vulnerability in ShapedPlugin, LLC Product Slider Pro for WooCommerce allows Malicious Software Implanted. This issue affects Product Slider Pro for WooCommerce: from n/a before 3.5.3. No patched version is available - the vendor has applied a fix to an existing release without publishing a new version. While the patch provided by the vendor is valid, releasing it under the existing version number leaves users unable to reliably determine whether they are running a patched or vulnerable installation. As a result, we treat this as an unpatched version.

Published: 6/5/2026, 9:16:26 AM
Last modified: 6/5/2026, 1:26:42 PM

References

HomeEventsBlogResourcesTeam