WordPress Plugin Flaw Exposes Sensitive Data Across 800,000+ Sites
ID: e1f98195-6889-5ab0-8651-8bbb341aeb25
STIX ID: report--e1f98195-6889-5ab0-8651-8bbb341aeb25
Feed Name: GBHackers
Threat Score
A vulnerability (CVE-2026-3098) in the Smart Slider 3 WordPress plugin allows authenticated users with subscriber-level privileges to perform arbitrary file reads via the plugin's export functionality, risking exposure of wp-config.php and database credentials. The flaw is due to missing capability checks during the export process; it affects versions 3.5.1.33 and earlier and has been patched in 3.5.1.34 (released March 24, 2026). Administrators are urged to update immediately.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
