Skip to main content
Live Webinar with SANS (June 25)— Agentic CTI Automation for Fun & ProfitRegister Free
Mallory
Back to intelligence
internet-facing-service-vulnerabilitydetection-content-updatewidely-deployed-product-advisorygovernment-vulnerability-catalog

Backdoor RCE Disclosed in WordPress Product Slider Pro for WooCommerce

Updated 14d agoFirst seen Jun 5, 20262 sources

A critical vulnerability tracked as CVE-2026-49777 was disclosed in ShapedPlugin's Product Slider Pro for WooCommerce WordPress plugin, with reports describing it as a backdoor and supply-chain remote code execution issue. The flaw was assigned CWE-1284 and a CVSS 3.1 score reflecting critical impact (AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H), indicating that attackers could potentially compromise confidentiality, integrity, and availability without authentication or user interaction.

Public reporting shows inconsistent affected-version boundaries, with one source listing versions before 3.5.3 and another identifying versions before 3.5.4, while a Nuclei template pull request labels the issue as KEV and ties it to active detection efforts. The CVE record also notes that the vendor said the issue was fixed in an existing release but did not clearly publish a definitive patched version, leaving defenders to verify plugin versions carefully and treat older deployments as potentially exposed until remediation guidance is clarified.

Share:
Backdoor RCE Disclosed in WordPress Product Slider Pro for WooCommerce
Stay ahead

Get ahead of threats like this

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.

EVENT TIMELINE

How this story unfolded

2 events from the most recent confirmed update back to the earliest known activity.

2 EVENTS
Jun 9, 202615d ago

Nuclei template PR references CVE-2026-49777 and version boundary update

On June 9, 2026, a GitHub pull request in the nuclei-templates repository referenced CVE-2026-49777 as a supply chain backdoor RCE in WordPress Product Slider Pro for WooCommerce. The visible content associates the issue with affected versions before 3.5.4, indicating an updated affected-version boundary in public detection content.

CVE-2026-49777 - WordPress Product Slider Pro for WooCommerce < 3.5.4 - Supply Chain Backdoor RCE (KEV) by DhiyaneshGeek · Pull Request #16354 · projectdiscovery/nuclei-templates · GitHub
Jun 5, 202619d ago

CVE-2026-49777 recorded for Product Slider Pro backdoor vulnerability

On June 5, 2026, CVE-2026-49777 was recorded for ShapedPlugin's Product Slider Pro for WooCommerce WordPress plugin. The CVE describes a backdoor-related vulnerability affecting versions before 3.5.3 and assigns CWE-1284 with a critical CVSS 3.1 score.

CVE-2026-49777 - WordPress Product Slider Pro for WooCommerce plugin < 3.5.3 - Backdoor vulnerability
LINKED ENTITIES

Related entities

Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.

6 LINKEDOpen in app
Affected products
1 linked
Woocommerce
Organizations
4 linked
GitHubDhiyaneshGeekPatchstackShapedPlugin, LLC
The operational view lives in Mallory

See the full picture, correlated to your attack surface.

This page covers what’s public. Mallory adds the parts that aren’t — which of your assets are affected, which threat actors are using it right now, which detections to deploy, and what to do next.
Exposure mapping

Map indicators from this story to your assets and identify affected systems in minutes.

Threat actor evidence

Every observed campaign, victim, and pivot linked to actors named in this story.

Associated malware

Malware, exploits, and IOCs connected to the activity described here.

Detection signatures

YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.

Scheduled alerts

Get matching new stories delivered to your team as they break — not the next morning.

AI threads

Ask questions about this story and take action on the answers.