File Read Vulnerability in SmartSlider Impacts 500K WordPress Sites

Vulnerability in the Smart Slider 3 WordPress plugin

Smart Slider 3 is one of the most popular WordPress plugins for creating and managing image sliders and content carousels. It offers an easy-to-use drag-and-drop editor and a rich set of templates to choose from.

A vulnerability tracked as CVE-2026-3098, was discovered and reported by researcher Dmitrii Ignatyev and impacts all versions of the Smart Slider 3 plugin through 3.5.1.33.

The vulnerability is said to be active on more than 800,000 websites, can be exploited to allow subscriber-level users access to arbitrary files on the server.

Key pointers unraveled include:

  • The vulnerability is of medium severity score due to requiring authentication
  • The vulnerability stems from missing capability checks in the plugin’s AJAX export actions
  • Allowing any authenticated user, including subscribers, to invoke them.
  • The presence of a nonce does not prevent abuse because it can be obtained by authenticated users.
  • The plugin was downloaded 303,428 times over the past week
  • Findings say target during such an attack is typically the wp-config.php file.

    Case of Privileged Escalation

    Hackers are always looking for ways to infiltrate and manipulate websites and Privilege Escalation is one of the ways and allows attackers to gain unauthorized access to sensitive areas of website.

    Privilege Escalation occurs when an attacker exploits flaw and further gain higher access permissions that were not granted previously.

    Hackers scan websites for weak configurations and outdated plugins or unpatched software that might allow them to bypass access restrictions.

    Remediation

    Website administrators must urgently verify their plugin library and update Smart Slider 3 to version 3.5.1.34 to prevent unauthorized data access.

    Scroll to top