CVE-2026-49777: critical vulnerability (CVSS 10.0)
CVE-2026-49777 in Product Slider Pro for WooCommerce (pre-3.5.4) allows attackers to exploit improper input validation, enabling malicious software injection. CVSS score: 10.0 (critical).
Immediate patching to version 3.5.4 or later is critical. Monitor for signs of exploitation, especially unauthorized scripts or unusual WooCommerce behavior. Consider WAF rules targeting input validation flaws.
The vulnerability stems from the improper validation of input quantities, which attackers can exploit to inject malicious software. This flaw exists in versions of Product Slider Pro for WooCommerce prior to 3.5.4.
Given the critical CVSS score of 10.0, exploitation risks are high, potentially leading to system compromise or data theft. Attackers may target e-commerce sites with this plugin installed.
Admins should upgrade to version 3.5.4 immediately and audit logs for signs of unusual or unauthorized activity. Employing a web application firewall (WAF) can help mitigate similar input validation vulnerabilities.