Critical severity10.0NVD Advisory· Published Jun 5, 2026· Updated Jun 8, 2026
CVE-2026-49777
CVE-2026-49777
Description
Improper Validation of Specified Quantity in Input vulnerability in ShapedPlugin, LLC Product Slider Pro for WooCommerce allows Malicious Software Implanted.
This issue affects Product Slider Pro for WooCommerce: from n/a before 3.5.4.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
3- Range: <3.5.3
- Range: <3.5.4
- Range: <3.5.4
Patches
Vulnerability mechanics
References
1News mentions
4- ShapedPlugin WordPress Pro Plugins Backdoored in Supply Chain AttackThe Hacker News · Jun 22, 2026
- ShapedPlugin update flow hacked to infect WordPress sitesBleepingComputer · Jun 18, 2026
- PSA: Supply Chain Compromise Targets ShapedPlugin, Backdoored Pro Plugins Distributed via Official ChannelsWordfence Blog · Jun 16, 2026
- Wordfence Intelligence Weekly WordPress Vulnerability Report (June 1, 2026 to June 7, 2026)Wordfence Blog · Jun 11, 2026