CVE-2026-49777
Deferred
Deferred - Pending Action
Malicious Software Implanted via Improper Input Validation in Product Slider Pro for WooCommerce
Publication date: 2026-06-05
Last updated on: 2026-06-08
Assigner: Patchstack
Description
Description
Improper Validation of Specified Quantity in Input vulnerability in ShapedPlugin, LLC Product Slider Pro for WooCommerce allows Malicious Software Implanted.
This issue affects Product Slider Pro for WooCommerce: from n/a before 3.5.4.
CVSS Scores
EPSS Scores
| Probability: | |
| Percentile: |
Meta Information
Affected Vendors & Products
| Vendor | Product | Version / Range |
|---|---|---|
| shapedplugin | product_slider_pro_for_woocommerce | to 3.5.3 (exc) |
Helpful Resources
Exploitability
| CWE ID | Description |
|---|---|
| CWE-1284 | The product receives input that is expected to specify a quantity (such as size or length), but it does not validate or incorrectly validates that the quantity has the required properties. |