PT-2026-28418 · WordPress · Smart Slider 3

·

CVE-2026-3098

·

Publicado

2026-03-26

·

Atualizado

2026-04-12

CVSS v3.1

6.5

Média

VetorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions Smart Slider 3 versions prior to 3.5.1.34
Description The Smart Slider 3 plugin for WordPress contains a flaw that allows authenticated attackers with Subscriber-level access or higher to read arbitrary files on the server. This is possible through the actionExportAll function, which lacks sufficient file type and source validation. The issue could lead to the exposure of sensitive information, such as database credentials contained in the wp-config.php file. Approximately 500,000 to 800,000 sites are estimated to be affected. Real-world exploitation of this issue has been observed, with attackers gaining access to wp-config.php files and escalating privileges. The actionExportAll function is the entry point for this issue. The vulnerable parameter is not explicitly mentioned.
Recommendations Update Smart Slider 3 to version 3.5.1.34 or later. Regenerate WordPress salts after updating the plugin.

Correção

Missing Authorization

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2026-3098

Produtos afetados

Smart Slider 3