CVE-2026-49777
CRITICAL 10.0EPSS 1.7%
Improper Validation of Specified Quantity in Input vulnerability in ShapedPlugin, LLC Product Slider Pro for WooCommerce allows Malicious Software Implanted. This issue affects Product Slider Pro for WooCommerce: from n/a before 3.5.4.
- CVSS v3.1
- 10.0 CRITICAL
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H - EPSS
- 1.66% chance of exploitation in the next 30 days, 75th percentile
- Nuclei
- critical · CWE-506
- Published
- 2026-06-05
- Updated
- 2026-06-08
Proof-of-concept exploits (2)
- xxconi/CVE-2026-49777-CVE-2026-107350★ · 2026-06-21
- izxci/CVE-2026-497770★ · 2026-06-12