WordPress Vulnerability Report: Arbitrary File Read in Smart Slider 3
On February 23, 2026, a serious vulnerability was discovered in the Smart Slider 3 plugin for WordPress, which boasts over 800,000 active installations. This flaw allows authenticated users with subscriber-level access or higher to read arbitrary files on the server, potentially exposing sensitive information.
The affected component is Smart Slider 3 versions up to 3.5.1.33. The risk of this vulnerability is rated as medium, with a CVSS score of 6.5, meaning attackers could access critical files like the site’s configuration data.
A fix was released on March 24, 2026, with version 3.5.1.34 addressing the issue. Users are urged to update their plugins immediately to safeguard their sites.
In summary, this vulnerability poses a significant risk, and timely updates are essential for maintaining security.
Source: View Original Report
