logo

File read flaw in Smart Slider plugin impacts 500K WordPress sites

ID: d59b9822-9115-53b0-8923-a4e54119fca1

STIX ID: report--d59b9822-9115-53b0-8923-a4e54119fca1

Feed Name: Bleeping Computer

Threat Score
65/100

Date Published: 2026-03-29

Date Updated: 2026-04-20

Author: Bill Toulas

...
...

A file-read vulnerability (CVE-2026-3098) in the Smart Slider 3 WordPress plugin (<= 3.5.1.33) allows any authenticated user, including subscribers, to export and read arbitrary server files—potentially exposing wp-config.php and database credentials. Wordfence validated a proof-of-concept and the vendor released a patch in version 3.5.1.34, but roughly 500,000 sites are estimated to still run vulnerable versions, so prompt patching is advised.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.