CVE-2026-49777 PUBLISHED

WordPress Product Slider Pro for WooCommerce plugin < 3.5.3 - Backdoor vulnerability

Assigner: Patchstack
Reserved: 01.06.2026 Published: 05.06.2026 Updated: 05.06.2026

Improper Validation of Specified Quantity in Input vulnerability in ShapedPlugin, LLC Product Slider Pro for WooCommerce allows Malicious Software Implanted.

This issue affects Product Slider Pro for WooCommerce: from n/a before 3.5.3.

No patched version is available - the vendor has applied a fix to an existing release without publishing a new version. While the patch provided by the vendor is valid, releasing it under the existing version number leaves users unable to reliably determine whether they are running a patched or vulnerable installation. As a result, we treat this as an unpatched version.

Metrics

CVSS Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
CVSS Score: 10

Product Status

Vendor ShapedPlugin, LLC
Product Product Slider Pro for WooCommerce
Versions Default: unaffected
  • affected from n/a to 3.5.3 (excl.)

Credits

  • Shane | Patchstack Bug Bounty Program finder

References

Problem Types

  • CWE-1284 Improper Validation of Specified Quantity in Input CWE

Impacts

  • CAPEC-523 Malicious Software Implanted