By using this site, you agree to the Privacy Policy and Terms of Use.
Accept
Viral Trending contentViral Trending content
  • Home
  • World News
  • Politics
  • Sports
  • Celebrity
  • Business
  • Crypto
  • Gaming News
  • Tech News
  • Travel
Reading: File read flaw in Smart Slider plugin impacts 500K WordPress sites
Notification Show More
Viral Trending contentViral Trending content
  • Home
  • Categories
    • World News
    • Politics
    • Sports
    • Celebrity
    • Business
    • Crypto
    • Tech News
    • Gaming News
    • Travel
  • Bookmarks
© 2024 All Rights reserved | Powered by Viraltrendingcontent
Viral Trending content > Blog > Tech News > File read flaw in Smart Slider plugin impacts 500K WordPress sites
Tech News

File read flaw in Smart Slider plugin impacts 500K WordPress sites

By admin 4 Min Read
Share
SHARE

A vulnerability in the Smart Slider 3 WordPress plugin, active on more than 800,000 websites, can be exploited to allow subscriber-level users access to arbitrary files on the server.

An authenticated attacker could use it to access sensitive files, such as wp-config.php, which includes database credentials, keys, and salt data, creating the risk for user data theft and complete website takeover.

Smart Slider 3 is one of the most popular WordPress plugins for creating and managing image sliders and content carousels. It offers an easy-to-use drag-and-drop editor and a rich set of templates to choose from.

The security issue, tracked as CVE-2026-3098, was discovered and reported by researcher Dmitrii Ignatyev and impacts all versions of the Smart Slider 3 plugin through 3.5.1.33.

It received a medium severity score due to requiring authentication. However, this only limits the impact to websites with membership or subscription options, a feature that is common on many platforms these days.

The vulnerability stems from missing capability checks in the plugin’s AJAX export actions. This allows any authenticated user, including subscribers, to invoke them.

According to researchers at WordPress security company Defiant, the developer of the Wordfence security plugin, the ‘actionExportAll’ function lacks file type and source validation, thus allowing arbitrary server files to be read and added to the export archive.

The presence of a nonce does not prevent abuse because it can be obtained by authenticated users.

“Unfortunately, this function does not include any file type or file source checks in the vulnerable version. This means that not only image or video files can be exported, but .php files can as well,” says István Márton, a vulnerability research contractor at Defiant.

“This ultimately makes it possible for authenticated attackers with minimal access, like subscribers, to read any arbitrary file on the server, including the site’s wp-config.php file, which contains the database credentials as well as keys and salts for cryptographic security.”

500K websites still vulnerable

On February 23, Ignatyev reported his findings to Wordfence, whose researchers validated the provided proof-of-concept exploit and informed Nextendweb, the developer of Smart Slider 3.

Nextendweb acknowledged the report on March 2 and on March 24 delivered a patch with the release of Smart Slider version 3.5.1.34.

According to WordPress.org stats, the plugin was downloaded 303,428 times over the past week. This means that at least 500,000 WordPress sites are running a vulnerable version of the Smart Slider 3 plugin and are exposed to attacks.

CVE-2026-3098 is not flagged as actively exploited as of writing, but the status may change soon, so prompt action is required by website owners/administrations.

tines

Automated pentesting proves the path exists. BAS proves whether your controls stop it. Most teams run one without the other.

This whitepaper maps six validation surfaces, shows where coverage ends, and provides practitioners with three diagnostic questions for any tool evaluation.

You Might Also Like

5 new WhatsApp Features you Should Start Using

10 Hidden iOS 26.4 Features You Should Be Using on Your iPhone

TeamPCP Hacks Checkmarx GitHub Actions Using Stolen CI Credentials

Why cybersecurity needs to adapt in the age of AI

A School District Tried to Help Train Waymos to Stop for School Buses. It Didn’t Work

TAGGED: Information Disclosure, Plugin, Vulnerability, WordPress
Share This Article
Facebook Twitter Copy Link
Previous Article Closing the ‘deterrence gap’: German military association calls for war economy
Next Article 10 Hidden iOS 26.4 Features You Should Be Using on Your iPhone
Leave a comment

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

- Advertisement -
Ad image

Latest News

5 new WhatsApp Features you Should Start Using
Tech News
10 Hidden iOS 26.4 Features You Should Be Using on Your iPhone
Tech News
Closing the ‘deterrence gap’: German military association calls for war economy
Business
Chelsea problems on the pitch are clear in recent stats lists – opinion
Sports
Market trading guide: Buy ACME Solar and Dalmia Bharat on Monday for short-term gains up to 16%. Here’s why
Business
EU ministers weigh oil price cap and windfall tax to rein in soaring energy costs
World News
Ethereum builders propose ‘economic zone’ to tackle L2 fragmentation
Crypto

About Us

Welcome to Viraltrendingcontent, your go-to source for the latest updates on world news, politics, sports, celebrity, tech, travel, gaming, crypto news, and business news. We are dedicated to providing you with accurate, timely, and engaging content from around the globe.

Quick Links

  • Home
  • World News
  • Politics
  • Celebrity
  • Business
  • Home
  • World News
  • Politics
  • Sports
  • Celebrity
  • Business
  • Crypto
  • Gaming News
  • Tech News
  • Travel
  • Sports
  • Crypto
  • Tech News
  • Gaming News
  • Travel

Trending News

cageside seats

Unlocking the Ultimate WWE Experience: Cageside Seats News 2024

5 new WhatsApp Features you Should Start Using

Investing £5 a day could help me build a second income of £329 a month!

cageside seats
Unlocking the Ultimate WWE Experience: Cageside Seats News 2024
May 22, 2024
5 new WhatsApp Features you Should Start Using
March 29, 2026
Investing £5 a day could help me build a second income of £329 a month!
March 27, 2024
Brussels unveils plans for a European Degree but struggles to explain why
March 27, 2024
© 2024 All Rights reserved | Powered by Vraltrendingcontent
  • About Us
  • Contact US
  • Disclaimer
  • Privacy Policy
  • Terms of Service
Welcome Back!

Sign in to your account

Lost your password?