216.73.216.6

CVE-2026-49777

· Published 05/06/2026 09:16 · Modified 05/06/2026 13:26

Labels: CVE-2026-49777 2026-06-05CVE-2026-49777CWE-1284[email protected]

Essential information

Published
05/06/2026 09:16
Modified
05/06/2026 13:26
Author
Creator
CVSS
10.0 CRITICAL (v3.1)
CISA KEV
No
CWE
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H

CVSS metrics

Description

Improper Validation of Specified Quantity in Input vulnerability in ShapedPlugin, LLC Product Slider Pro for WooCommerce allows Malicious Software Implanted. This issue affects Product Slider Pro for WooCommerce: from n/a before 3.5.3. No patched version is available - the vendor has applied a fix to an existing release without publishing a new version. While the patch provided by the vendor is valid, releasing it under the existing version number leaves users unable to reliably determine whether they are running a patched or vulnerable installation. As a result, we treat this as an unpatched version.

NVD status

Status
Deferred — CVE has been recently published to the CVE List and has been received by the NVD.
Source
[email protected]
NVD
View on NVD

Affected products (CPE)

ProductCPE
shapedplugin / product slider pro for woocommerce cpe:2.3:a:shapedplugin:product_slider_pro_for_woocommerce:<3.5.3:*:*:*:*:*:*:*

References