CVE-2026-49777: WordPress Product Slider Pro for WooCommerce plugin < 3.5.4 - Backdoor vulnerability
Improper Validation of Specified Quantity in Input vulnerability in ShapedPlugin, LLC Product Slider Pro for WooCommerce allows Malicious Software Implanted.
This issue affects Product Slider Pro for WooCommerce: from n/a before 3.5.4.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
ShapedPlugin, LLC Product Slider Pro for WooCommerceto a version that resolves this vulnerability.Fixed in 3.5.4
Event History
Frequently Asked Questions
What is the severity of CVE-2026-49777?
CVE-2026-49777 has a critical severity rating of 10 according to the CVSS score.
What is the risk associated with CVE-2026-49777?
CVE-2026-49777 has a risk score of 87, indicating a significant threat level.
How do I fix CVE-2026-49777?
Currently, there is no patched version available for CVE-2026-49777, and users are advised to mitigate risks while awaiting a fix.
What software is affected by CVE-2026-49777?
CVE-2026-49777 affects the Product Slider Pro for WooCommerce plugin developed by ShapedPlugin, specifically versions before 3.5.3.
What type of vulnerability is CVE-2026-49777?
CVE-2026-49777 is categorized as an Improper Validation of Specified Quantity in Input vulnerability, potentially allowing for backdoor access.