800K Sites at Risk: Smart Slider 3 Plugin File Read Flaw

Date:

WordPress Vulnerability Report: Arbitrary File Read in Smart Slider 3

On February 23, 2026, a serious vulnerability was discovered in the Smart Slider 3 plugin for WordPress, which boasts over 800,000 active installations. This flaw allows authenticated users with subscriber-level access or higher to read arbitrary files on the server, potentially exposing sensitive information.

The affected component is Smart Slider 3 versions up to 3.5.1.33. The risk of this vulnerability is rated as medium, with a CVSS score of 6.5, meaning attackers could access critical files like the site’s configuration data.

A fix was released on March 24, 2026, with version 3.5.1.34 addressing the issue. Users are urged to update their plugins immediately to safeguard their sites.

In summary, this vulnerability poses a significant risk, and timely updates are essential for maintaining security.

Source: View Original Report

Share post:

spot_imgspot_img

Popular

More like this
Related

WPScan 4.0.0: Critical XSS Vulnerability Exposed!

WordPress Vulnerability Report: WPScan 4.0.0 Released Introduction The latest version of...

119 Edge Extensions: Malware Disguised as Useful Tools

Cybersecurity Alert: Malware Infiltrates Popular Browser Extensions A recent malware...

200K WordPress Sites Face XSS Risk from Burst Statistics Plugin

Critical Vulnerability Discovered in Burst Statistics Plugin for WordPress On...

Foxconn Cyberattack: Nitrogen Ransomware Strikes WordPress Sites

Cyberattack Hits Foxconn: Major Data Breach Reported Foxconn, the largest...