WordPress Plugin Vulnerability Exposes Sensitive Data From 800,000+ Sites
ID: 5e52c096-64e7-5892-b4e3-16a945e12055
STIX ID: report--5e52c096-64e7-5892-b4e3-16a945e12055
Feed Name: cybersecurityNews.com
A medium-severity authenticated arbitrary file read vulnerability (CVE-2026-3098) was disclosed in the Smart Slider 3 WordPress plugin (≈800,000 installs). The flaw in the plugin's export workflow and lack of capability checks allows authenticated low-privilege users to export arbitrary server files (including wp-config.php), risking full site compromise; the issue was responsibly disclosed by a researcher, Wordfence issued temporary firewall protections, and Nextend released a patched plugin version 3.5.1.34 on March 24, 2026.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
