CVE-2026-49777
CRITICAL EXPLOITED NUCLEIWordPress Product Slider Pro for WooCommerce plugin < 3.5.3 - Backdoor vulnerability
Title source: cnaExploitation Summary
CVE-2026-49777 has been observed exploited in the wild (reported by VulnCheck KEV). EIP tracks 4 public exploits from researchers including amnsecurity, HORKimhab, xxconi. A Nuclei detection template is also available.
AI-analyzed exploit summary This PoC exploits CVE-2026-49777, an unauthenticated remote code execution vulnerability in WooCommerce Product Slider Pro plugin. The exploit triggers a malicious software download from a remote server via unprotected AJAX endpoints, leading to arbitrary code execution on the target WordPress site.
Description
Improper Validation of Specified Quantity in Input vulnerability in ShapedPlugin, LLC Product Slider Pro for WooCommerce allows Malicious Software Implanted. This issue affects Product Slider Pro for WooCommerce: from n/a before 3.5.4.
Exploits (4)
This PoC exploits CVE-2026-49777, an unauthenticated remote code execution vulnerability in WooCommerce Product Slider Pro plugin. The exploit triggers a malicious software download from a remote server via unprotected AJAX endpoints, leading to arbitrary code execution on the target WordPress site.
The repository lacks actual exploit code or technical details about CVE-2026-49777. It provides generic setup instructions and references an external script for cleanup, which is a common tactic in suspicious repos.
This repository contains a functional exploit for CVE-2026-49777, targeting a WordPress supply chain vulnerability involving ShapedPlugin. The exploit demonstrates authentication bypass via a hardcoded MD5 hash, REST API backdoor file write, and webshell-based remote code execution.
The repository provides a detailed technical analysis of CVE-2026-49777, a backdoor RCE vulnerability in ShapedPlugin Product Slider Pro for WooCommerce, attributed to improper input validation (CWE-1284). It includes affected versions, patch status, CVSS scoring, and mentions an exploit script but does not provide functional code.
Nuclei Templates (1)
http.component:"WordPress"
body="wp-content/plugins/woo-product-slider-pro"
References (1)
Scores
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H