CVE-2026-49777

CRITICAL EXPLOITED NUCLEI

WordPress Product Slider Pro for WooCommerce plugin < 3.5.3 - Backdoor vulnerability

Title source: cna
STIX 2.1

Exploitation Summary

CVE-2026-49777 has been observed exploited in the wild (reported by VulnCheck KEV). EIP tracks 4 public exploits from researchers including amnsecurity, HORKimhab, xxconi. A Nuclei detection template is also available.

AI-analyzed exploit summary This PoC exploits CVE-2026-49777, an unauthenticated remote code execution vulnerability in WooCommerce Product Slider Pro plugin. The exploit triggers a malicious software download from a remote server via unprotected AJAX endpoints, leading to arbitrary code execution on the target WordPress site.

Description

Improper Validation of Specified Quantity in Input vulnerability in ShapedPlugin, LLC Product Slider Pro for WooCommerce allows Malicious Software Implanted. This issue affects Product Slider Pro for WooCommerce: from n/a before 3.5.4.

Exploits (4)

nomisec WORKING POC
by amnsecurity · poc
https://github.com/amnsecurity/CVE-2026-49777-WooCommerce-RCE

This PoC exploits CVE-2026-49777, an unauthenticated remote code execution vulnerability in WooCommerce Product Slider Pro plugin. The exploit triggers a malicious software download from a remote server via unprotected AJAX endpoints, leading to arbitrary code execution on the target WordPress site.

Classification
Working Poc 95%
Attack Type
Rce
Complexity
Trivial
Reliability
Reliable
Target: WooCommerce Product Slider Pro for WordPress (versions 1.0.0 through 2.2.0)
No auth needed
Prerequisites: Target must have WooCommerce Product Slider Pro plugin installed (vulnerable versions) · Target server must be able to make outbound HTTP requests to attacker-controlled server
mistral-large-3 · analyzed Jul 08, 2026 Full analysis →
nomisec SUSPICIOUS
by HORKimhab · poc
https://github.com/HORKimhab/CVE-Wordpress

The repository lacks actual exploit code or technical details about CVE-2026-49777. It provides generic setup instructions and references an external script for cleanup, which is a common tactic in suspicious repos.

Classification
Suspicious 90%
Attack Type
Other
Complexity
Theoretical
Reliability
Theoretical
Target: WordPress (unspecified version)
No auth needed
Prerequisites: none specified
mistral-large-3 · analyzed Jun 24, 2026 Full analysis →
github WORKING POC
by xxconi · pythonremote
https://github.com/xxconi/CVE-2026-49777-CVE-2026-10735

This repository contains a functional exploit for CVE-2026-49777, targeting a WordPress supply chain vulnerability involving ShapedPlugin. The exploit demonstrates authentication bypass via a hardcoded MD5 hash, REST API backdoor file write, and webshell-based remote code execution.

Classification
Working Poc 95%
Attack Type
Rce
Complexity
Moderate
Reliability
Reliable
Target: WordPress with vulnerable ShapedPlugin components (e.g., WooCommerce Subscription, WooCommerce Notification)
No auth needed
Prerequisites: WordPress installation with vulnerable plugins · Network access to the target
mistral-large-3 · analyzed Jun 21, 2026 Full analysis →
github WRITEUP
by izxci · poc
https://github.com/izxci/CVE-2026-49777

The repository provides a detailed technical analysis of CVE-2026-49777, a backdoor RCE vulnerability in ShapedPlugin Product Slider Pro for WooCommerce, attributed to improper input validation (CWE-1284). It includes affected versions, patch status, CVSS scoring, and mentions an exploit script but does not provide functional code.

Classification
Writeup 90%
Attack Type
Rce
Complexity
Moderate
Reliability
Theoretical
Target: ShapedPlugin Product Slider Pro for WooCommerce < 3.5.3
No auth needed
Prerequisites: network access to vulnerable WooCommerce instance
mistral-large-3 · analyzed Jun 12, 2026 Full analysis →

Nuclei Templates (1)

WordPress Product Slider Pro for WooCommerce < 3.5.4 - Supply Chain Backdoor RCE
CRITICALVERIFIEDby DhiyaneshDk
Shodan: http.component:"WordPress"
FOFA: body="wp-content/plugins/woo-product-slider-pro"

Scores

CVSS v3 10.0
EPSS 0.0166
EPSS Percentile 74.3%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable yes
Technical Impact total

Details

VulnCheck KEV 2026-06-05
CWE
CWE-1284
Status published
Products (2)
ShapedPlugin, LLC/Product Slider Pro for WooCommerce < 3.5.3
ShapedPlugin, LLC/Product Slider Pro for WooCommerce < 3.5.4
Published Jun 05, 2026
Tracked Since Jun 05, 2026