CVE-2026-49777 is a critical supply-chain backdoor vulnerability affecting the commercial Product Slider Pro for WooCommerce WordPress plugin from ShapedPlugin, LLC. The issue affects releases prior to 3.5.4, with reporting also noting that all versions through 3.5.2 were affected and that version 3.5.3 is not reliably distinguishable as safe because the vendor reportedly modified an existing release in place without issuing a new version identifier. The vulnerability is classified as CWE-1284 and is described as improper validation of a quantity-related input that enabled malicious software implantation. Available reporting indicates the compromised plugin distribution contained backdoor functionality that could be triggered remotely without authentication, leading to installation of attacker-controlled code on affected WordPress sites. The issue is best understood as a maliciously backdoored premium plugin release delivered through the vendor’s official distribution channel rather than a routine isolated coding defect.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
2 valid exploits after Mallory filtered fakes, detection scripts, and README-only repos (2 hidden).
Small single-purpose exploit repository with 4 files: one Python exploit script, a README, license, and .gitignore. The main artifact is CVE-2026-49777.py, a standalone Python CLI tool using requests, argparse, and helper print/URL-normalization routines. Based on the visible code and README, it supports two phases: (1) detection/version checking of the Product Slider Pro for WooCommerce WordPress plugin and (2) active exploitation that attempts to trigger an unauthenticated remote payload download/execution path associated with CVE-2026-49777. The script includes a hardcoded vulnerable version list covering 1.0.0-1.3.1 and 2.0.0-2.2.0, supports check-only mode, optional proxying, timeout/banner options, and reports success/failure to the operator. The exploit is not part of a larger framework and appears to be an operational PoC rather than a mere detector, because it contains explicit exploitation logic intended to trigger remote code execution on the target. The README mirrors the exploit purpose in Arabic and English, documents usage, affected versions, remediation guidance, and lists post-compromise indicators such as suspicious files under the plugin cache directory and uploads directory.
Repository contains a single Python exploit script and a minimal README. The main file, CVE-2026-49777.py, is a standalone interactive exploitation tool targeting an alleged ShapedPlugin supply-chain compromise / LicenseLoader RCE affecting WordPress plugin deployments. The script is not part of a known exploitation framework. Structurally, the script includes: banner/UI code; logging helpers; result persistence to pwned.txt; IOC detection logic; login-bypass logic using a hardcoded MD5 value; RCE-related constants including a WooCommerce-style REST path (/wp-json/wc/v3/settings/apply), a command parameter key (wc_diag), and a header artifact (X-Cache-Status); single-target exploitation flow; and multithreaded bulk scanning from a user-supplied target list. The visible code shows the exploit first probing targets for compromise indicators by requesting fake plugin directories and specific PHP files under /wp-content/plugins/. It also checks the site root for an X-Cache-Status header whose 8-character alphanumeric value is treated as confirmation of header-based RCE behavior. The script then attempts a login bypass against an admin username using a hardcoded MD5 hash and proceeds toward command execution with an operator-supplied command, defaulting to id. Successful targets are recorded in pwned.txt. Overall purpose: this is an operational exploit/scanner for compromised WordPress sites, combining detection and exploitation. It supports both validation of infection/backdoor artifacts and active post-compromise command execution across one or many targets.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
11 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A critical supply chain compromise affecting Product Slider Pro for WooCommerce, where malicious backdoor code was injected into official Pro plugin releases distributed through the vendor's licensed update channel.
A related backdoor vulnerability associated with the ShapedPlugin supply-chain compromise impacting multiple premium WordPress plugins.
A supply-chain backdoor remote code execution vulnerability affecting WordPress Product Slider Pro for WooCommerce versions earlier than 3.5.4.
A vulnerability in ShapedPlugin Product Slider Pro for WooCommerce that allows malicious software implantation, affecting versions before 3.5.3.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.