plugin

Smart Slider 3 Vulnerabilities

20 known security issues reported for the Smart Slider 3 WordPress plugin. Most recent disclosed Aug 27, 2026.

2 high 11 medium

Running Smart Slider 3 on your site? Check whether your installed version is affected.

Scan your site free

Smart Slider 3 <= 3.5.1.38 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'slider' Block Attribute

medium

The Smart Slider 3 plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'slider' Block Attribute in all versions up to, and including, 3.5.1.38 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above, to inj...

CVSS:
6.4
Affected:
up to 3.5.1.38
Fixed in:
3.5.1.39
Disclosed:
Aug 27, 2026

CVE-2026-15798 on NVD →

Smart Slider 3 <= 3.5.1.37 - Missing Authorization to Authenticated (Contributor+) Sensitive Information Exposure via WP_Query Parameter Injection via 'keyword' Parameter

medium

The Smart Slider 3 plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 3.5.1.37 via the 'keyword' parameter. This makes it possible for authenticated attackers, with contributor-level access and above, to extract titles and full content excerpts of private, draft,...

CVSS:
4.3
Affected:
up to 3.5.1.37
Fixed in:
3.5.1.38
Disclosed:
Jul 13, 2026

CVE-2026-12385 on NVD →

Smart Slider 3 <= 3.5.1.36 - Authenticated (Administrator+) Path Traversal to Arbitrary File Read via 'src'/'srcset' Attribute in HTML Export

medium

The Smart Slider 3 plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 3.5.1.36 via the replaceHTMLImage function. This makes it possible for authenticated attackers, with administrator-level access and above, to read the contents of arbitrary files on the server, which can c...

CVSS:
4.9
Affected:
up to 3.5.1.36
Fixed in:
3.5.1.37
Disclosed:
Jun 5, 2026

CVE-2026-9197 on NVD →

Smart Slider 3 <= 3.5.1.33 - Missing Authorization to Authenticated (Contributor+) Slider Data Read and Image Record Manipulation

medium

The Smart Slider 3 plugin for WordPress is vulnerable to unauthorized access and modification of data due to missing capability checks on multiple wp_ajax_smart-slider3 controller actions in all versions up to, and including, 3.5.1.33. The display_admin_ajax() method does not call checkForCap() (which requires unfilter...

CVSS:
5.4
Affected:
up to 3.5.1.33
Fixed in:
3.5.1.34
Disclosed:
Apr 7, 2026

CVE-2026-4065 on NVD →

Smart Slider 3 - Authenticated (Subscriber+) Arbitrary File Read via actionExportAll vulnerability

medium

Authenticated (Subscriber+) Arbitrary File Read via actionExportAll vulnerability

CVSS:
6.5
Affected:
up to 3.5.1.33
Fixed in:
3.5.1.34
Disclosed:
Mar 27, 2026

Smart Slider 3 <= 3.5.1.33 - Authenticated (Subscriber+) Arbitrary File Read via actionExportAll

medium

The Smart Slider 3 plugin for WordPress is vulnerable to Arbitrary File Read in all versions up to, and including, 3.5.1.33 via the 'actionExportAll' function. This makes it possible for authenticated attackers, with Subscriber-level access and above, to read the contents of arbitrary files on the server, which can con...

CVSS:
6.5
Affected:
up to 3.5.1.33
Fixed in:
3.5.1.34
Disclosed:
Mar 26, 2026

CVE-2026-3098 on NVD →

Smart Slider 3 <= 3.5.1.28 - Authenticated (Administrator+) SQL Injection via `sliderid` Parameter

medium

The Smart Slider 3 plugin for WordPress is vulnerable to time-based SQL Injection via the ‘sliderid’ parameter in all versions up to, and including, 3.5.1.28 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticate...

CVSS:
4.9
Affected:
up to 3.5.1.28
Fixed in:
3.5.1.29
Disclosed:
Jul 29, 2025

CVE-2025-6348 on NVD →

Smart Slider 3 [smart-slider-3] < 3.5.1.23

unknown

[en] The Smart Slider 3 plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the upload function in all versions up to, and including, 3.5.1.22. This makes it possible for authenticated attackers, with contributor-level access and above, to upload files, including...

Affected:
up to 3.5.1.23
Fixed in:
3.5.1.23
Disclosed:
Apr 13, 2024

CVE-2024-3027 on NVD →

Smart Slider 3 <= 3.5.1.22 - Missing Authorization to Limited File Upload

medium

The Smart Slider 3 plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the upload function in all versions up to, and including, 3.5.1.22. This makes it possible for authenticated attackers, with contributor-level access and above, to upload files, including SVG...

CVSS:
6.4
Affected:
up to 3.5.1.22
Fixed in:
3.5.1.23
Disclosed:
Apr 12, 2024

CVE-2024-3027 on NVD →

Smart Slider 3 [smart-slider-3] < 3.5.1.11

unknown

[en] Deserialization of Untrusted Data vulnerability in Nextend Smart Slider 3.This issue affects Smart Slider 3: from n/a through 3.5.1.9.

Affected:
up to 3.5.1.11
Fixed in:
3.5.1.11
Disclosed:
Jan 19, 2024

CVE-2022-45845 on NVD →

Smart Slider 3 [smart-slider-3] < 3.5.1.14

unknown

[en] The Smart Slider 3 WordPress plugin before 3.5.1.14 does not properly validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks

Affected:
up to 3.5.1.14
Fixed in:
3.5.1.14
Disclosed:
Mar 27, 2023

CVE-2023-0660 on NVD →

Smart Slider 3 [smart-slider-3] < 3.5.1.11

unknown

[en] Auth. (contributor+) Stored Cross-Site Scripting vulnerability in Nextend Smart Slider 3 plugin <= 3.5.1.9 versions.

Affected:
up to 3.5.1.11
Fixed in:
3.5.1.11
Disclosed:
Mar 23, 2023

CVE-2022-45843 on NVD →

Smart Slider 3 <= 3.5.1.13 - Authenticated (Contributor+) Stored Cross-Site Scripting

medium

The Smart Slider 3 plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's shortcode(s) in versions up to, and including, 3.5.1.13 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers with contributor-level...

CVSS:
6.4
Affected:
up to 3.5.1.13
Fixed in:
3.5.1.14
Disclosed:
Feb 28, 2023

CVE-2023-0660 on NVD →

Smart Slider 3 <= 3.5.1.9 - Authenticated (Contributor+) PHP Object Injection

high

The Smart Slider 3 plugin for WordPress is vulnerable to PHP Object Injection in versions up to, and including, 3.5.1.9 via deserialization of untrusted input. This allows contributor-level attackers to inject a PHP Object. No POP chain is present in the vulnerable plugin. If a POP chain is present via an additional p...

CVSS:
8.8
Affected:
up to 3.5.1.9
Fixed in:
3.5.1.11
Disclosed:
Nov 23, 2022

CVE-2022-45845 on NVD →

Smart Slider 3 <= 3.5.1.9 - Authenticated (Contributor+) Stored Cross-Site Scripting

medium

The Smart Slider 3 plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 3.5.1.9 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level permissions and above, to inject arbitrary web scripts in...

CVSS:
6.4
Affected:
up to 3.5.1.9
Fixed in:
3.5.1.11
Disclosed:
Nov 23, 2022

CVE-2022-45843 on NVD →

Smart Slider 3 [smart-slider-3] < 3.5.1.11

unknown

[en] The Smart Slider 3 WordPress plugin before 3.5.1.11 unserialises the content of an imported file, which could lead to PHP object injection issues when a user import (intentionally or not) a malicious file, and a suitable gadget chain is present on the site.

Affected:
up to 3.5.1.11
Fixed in:
3.5.1.11
Disclosed:
Oct 31, 2022

CVE-2022-3357 on NVD →

Smart Slider 3 <= 3.5.1.9 - PHP Object Injection

high

The Smart Slider 3 plugin for WordPress is vulnerable to PHP Object Injection in versions up to, and including, 3.5.1.9 via deserialization of untrusted input when importing a file. This allows administrator-level attackers to inject a PHP Object. No POP chain is present in the vulnerable plugin. If a POP chain is pre...

CVSS:
7.2
Affected:
up to 3.5.1.9
Fixed in:
3.5.1.11
Disclosed:
Oct 10, 2022

CVE-2022-3357 on NVD →

Smart Slider 3 [smart-slider-3] < 3.5.0.9

unknown

[en] The Smart Slider 3 Free and pro WordPress plugins before 3.5.0.9 did not sanitise the Project Name before outputting it back in the page, leading to a Stored Cross-Site Scripting issue. By default, only administrator users could access the affected functionality, limiting the exploitability of the vulnerability. H...

Affected:
up to 3.5.0.9
Fixed in:
3.5.0.9
Disclosed:
Jun 14, 2021

CVE-2021-24382 on NVD →

Smart Slider 3 <= 3.5.0.8 - Authenticated Stored Cross-Site Scripting

medium

The Smart Slider 3 Free and pro WordPress plugins before 3.5.0.9 did not sanitise the Project Name before outputting it back in the page, leading to a Stored Cross-Site Scripting issue. By default, only administrator users could access the affected functionality, limiting the exploitability of the vulnerability. Howeve...

CVSS:
5.4
Affected:
up to 3.5.0.9
Fixed in:
3.5.0.9
Disclosed:
Jun 7, 2021

CVE-2021-24382 on NVD →

Smart Slider 3 [smart-slider-3] < 3.5.1.29

unknown
Affected:
up to 3.5.1.29
Fixed in:
3.5.1.29

CVE-2025-6348 on NVD →

Protect your WordPress site

Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.

Scan your site free

← Back to the vulnerability database