# CVE-2026-49777

## Summary

- **CVE ID:** CVE-2026-49777
- **Severity:** CRITICAL
- **CVSS Score:** 10 (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H)
- **CWE:** CWE-1284
- **Published:** Jun 5, 2026
- **Last Modified:** Jun 8, 2026

## Description

Improper Validation of Specified Quantity in Input vulnerability in ShapedPlugin, LLC Product Slider Pro for WooCommerce allows Malicious Software Implanted.

This issue affects Product Slider Pro for WooCommerce: from n/a before 3.5.3.

No patched version is available - the vendor has applied a fix to an existing release without publishing a new version. While the patch provided by the vendor is valid, releasing it under the existing version number leaves users unable to reliably determine whether they are running a patched or vulnerable installation. As a result, we treat this as an unpatched version.

## Affected Products

- ShapedPlugin, LLC — Product Slider Pro for WooCommerce (n/a)

## References

- [CNA](https://patchstack.com/database/wordpress/plugin/woo-product-slider-pro/vulnerability/wordpress-product-slider-pro-for-woocommerce-plugin-3-5-2-backdoor-vulnerability?_s_id=cve)

## Exploitation Prediction (EPSS)

- **EPSS Score:** 1.66%
- **EPSS Percentile:** 75.2

---
_Exported from OnDuty AI Vulnerability Intelligence on 2026-09-11._