CVE-2026-49777: exploitation status and patch state
CVE-2026-49777 · CVSS 10.0 CRITICAL · EPSS 2%
Improper Validation of Specified Quantity in Input vulnerability in ShapedPlugin, LLC Product Slider Pro for WooCommerce allows Malicious Software Implanted.
This issue affects Product Slider Pro for WooCommerce: from n/a before 3.5.4.
Is CVE-2026-49777 exploited?
Not in the CISA KEV catalog.
EPSS puts exploitation in the next 30 days at 2%.
Public exploit code: none found in monitored sources.