Junglewise Threat Intelligence

CVE-2026-49777: ShapedPlugin Product Slider Pro for WooCommerce backdoor vulnerability

CVE-2026-49777 · Severity: critical · CVSS 10 · Published 2026-06-05

Executive brief

A critical security flaw has been identified in a popular WooCommerce plugin used to display product sliders on e-commerce websites. This vulnerability acts as a 'backdoor,' allowing unauthorized individuals to remotely plant malicious software on the website. An exploit could lead to a total takeover of the site, theft of customer data, or the injection of malicious advertisements, severely damaging business operations and reputation.

Technical details

The Product Slider Pro for WooCommerce plugin (versions prior to 3.5.3) contains a backdoor vulnerability classified as Improper Validation of Specified Quantity in Input (CWE-1284). This flaw allows an unauthenticated remote attacker to execute arbitrary code or implant malicious software on the host server. The vulnerability is considered highly critical (CVSS 10.0) as it requires no user interaction or privileges to exploit. While the vendor has released a fix, they did not increment the version number, making it difficult for administrators to verify if their installation is protected. Security researchers recommend treating all installations of version 3.5.2 and below as potentially compromised.

Affected products

  • ShapedPlugin, LLC Product Slider Pro for WooCommerce before 3.5.3

Timeline

  • 2026-05-21: other: Reported by researcher Shane
  • 2026-06-04: advisory: Patchstack advisory published
  • 2026-06-05: disclosed: CVE published to NVD

References