logo

WordPress Plugin Vulnerability Exposes Sensitive Data From 800,000+ Sites

ID: 5e52c096-64e7-5892-b4e3-16a945e12055

STIX ID: report--5e52c096-64e7-5892-b4e3-16a945e12055

Feed Name: cybersecurityNews.com

Threat Score
70/100

Date Published: 2026-03-31

Date Updated: 2026-05-05

Author: Abinaya

...
...

A medium-severity authenticated arbitrary file read vulnerability (CVE-2026-3098) was disclosed in the Smart Slider 3 WordPress plugin (≈800,000 installs). The flaw in the plugin's export workflow and lack of capability checks allows authenticated low-privilege users to export arbitrary server files (including wp-config.php), risking full site compromise; the issue was responsibly disclosed by a researcher, Wordfence issued temporary firewall protections, and Nextend released a patched plugin version 3.5.1.34 on March 24, 2026.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.