logo

WordPress Plugin Flaw Exposes Sensitive Data Across 800,000+ Sites

ID: e1f98195-6889-5ab0-8651-8bbb341aeb25

STIX ID: report--e1f98195-6889-5ab0-8651-8bbb341aeb25

Feed Name: GBHackers

Threat Score
70/100

Date Published: 2026-03-30

Date Updated: 2026-04-22

Author: Divya

...
...

A vulnerability (CVE-2026-3098) in the Smart Slider 3 WordPress plugin allows authenticated users with subscriber-level privileges to perform arbitrary file reads via the plugin's export functionality, risking exposure of wp-config.php and database credentials. The flaw is due to missing capability checks during the export process; it affects versions 3.5.1.33 and earlier and has been patched in 3.5.1.34 (released March 24, 2026). Administrators are urged to update immediately.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.