800K Sites at Risk: Smart Slider 3 Plugin File Read Flaw

Date:

WordPress Vulnerability Report: Arbitrary File Read in Smart Slider 3

On February 23, 2026, a serious vulnerability was discovered in the Smart Slider 3 plugin for WordPress, which boasts over 800,000 active installations. This flaw allows authenticated users with subscriber-level access or higher to read arbitrary files on the server, potentially exposing sensitive information.

The affected component is Smart Slider 3 versions up to 3.5.1.33. The risk of this vulnerability is rated as medium, with a CVSS score of 6.5, meaning attackers could access critical files like the site’s configuration data.

A fix was released on March 24, 2026, with version 3.5.1.34 addressing the issue. Users are urged to update their plugins immediately to safeguard their sites.

In summary, this vulnerability poses a significant risk, and timely updates are essential for maintaining security.

Source: View Original Report

Share post:

spot_imgspot_img

Popular

More like this
Related

Critical PHP Object Injection Vulnerability Found in GiveWP Plugin

A recently discovered vulnerability in the GiveWP plugin poses...

AI Advances Strengthen Cybersecurity: Wordfence Unveils Critical Vulnerability Discovery

Wordfence has revealed significant advancements in its incorporation of...

Critical Unauthenticated Account Takeover Vulnerability Found in TranslatePress Plugin

On August 11, 2026, a significant security vulnerability was...

Hackers Target WordPress Sites in miniOrange Authentication Bypass Attacks

In recent weeks, hackers have escalated their attacks on...