Smart Slider 3 <= 3.5.1.38 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'slider' Block Attribute
medium
The Smart Slider 3 plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'slider' Block Attribute in all versions up to, and including, 3.5.1.38 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above, to inj...
- CVSS:
- 6.4
- Affected:
- up to 3.5.1.38
- Fixed in:
- 3.5.1.39
- Disclosed:
- Aug 27, 2026
CVE-2026-15798 on NVD →
Smart Slider 3 <= 3.5.1.37 - Missing Authorization to Authenticated (Contributor+) Sensitive Information Exposure via WP_Query Parameter Injection via 'keyword' Parameter
medium
The Smart Slider 3 plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 3.5.1.37 via the 'keyword' parameter. This makes it possible for authenticated attackers, with contributor-level access and above, to extract titles and full content excerpts of private, draft,...
- CVSS:
- 4.3
- Affected:
- up to 3.5.1.37
- Fixed in:
- 3.5.1.38
- Disclosed:
- Jul 13, 2026
CVE-2026-12385 on NVD →
Smart Slider 3 <= 3.5.1.36 - Authenticated (Administrator+) Path Traversal to Arbitrary File Read via 'src'/'srcset' Attribute in HTML Export
medium
The Smart Slider 3 plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 3.5.1.36 via the replaceHTMLImage function. This makes it possible for authenticated attackers, with administrator-level access and above, to read the contents of arbitrary files on the server, which can c...
- CVSS:
- 4.9
- Affected:
- up to 3.5.1.36
- Fixed in:
- 3.5.1.37
- Disclosed:
- Jun 5, 2026
CVE-2026-9197 on NVD →
Smart Slider 3 <= 3.5.1.33 - Missing Authorization to Authenticated (Contributor+) Slider Data Read and Image Record Manipulation
medium
The Smart Slider 3 plugin for WordPress is vulnerable to unauthorized access and modification of data due to missing capability checks on multiple wp_ajax_smart-slider3 controller actions in all versions up to, and including, 3.5.1.33. The display_admin_ajax() method does not call checkForCap() (which requires unfilter...
- CVSS:
- 5.4
- Affected:
- up to 3.5.1.33
- Fixed in:
- 3.5.1.34
- Disclosed:
- Apr 7, 2026
CVE-2026-4065 on NVD →
Smart Slider 3 - Authenticated (Subscriber+) Arbitrary File Read via actionExportAll vulnerability
medium
Authenticated (Subscriber+) Arbitrary File Read via actionExportAll vulnerability
- CVSS:
- 6.5
- Affected:
- up to 3.5.1.33
- Fixed in:
- 3.5.1.34
- Disclosed:
- Mar 27, 2026
Smart Slider 3 <= 3.5.1.33 - Authenticated (Subscriber+) Arbitrary File Read via actionExportAll
medium
The Smart Slider 3 plugin for WordPress is vulnerable to Arbitrary File Read in all versions up to, and including, 3.5.1.33 via the 'actionExportAll' function. This makes it possible for authenticated attackers, with Subscriber-level access and above, to read the contents of arbitrary files on the server, which can con...
- CVSS:
- 6.5
- Affected:
- up to 3.5.1.33
- Fixed in:
- 3.5.1.34
- Disclosed:
- Mar 26, 2026
CVE-2026-3098 on NVD →
Smart Slider 3 <= 3.5.1.28 - Authenticated (Administrator+) SQL Injection via `sliderid` Parameter
medium
The Smart Slider 3 plugin for WordPress is vulnerable to time-based SQL Injection via the ‘sliderid’ parameter in all versions up to, and including, 3.5.1.28 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticate...
- CVSS:
- 4.9
- Affected:
- up to 3.5.1.28
- Fixed in:
- 3.5.1.29
- Disclosed:
- Jul 29, 2025
CVE-2025-6348 on NVD →
Smart Slider 3 [smart-slider-3] < 3.5.1.23
unknown
[en] The Smart Slider 3 plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the upload function in all versions up to, and including, 3.5.1.22. This makes it possible for authenticated attackers, with contributor-level access and above, to upload files, including...
- Affected:
- up to 3.5.1.23
- Fixed in:
- 3.5.1.23
- Disclosed:
- Apr 13, 2024
CVE-2024-3027 on NVD →
Smart Slider 3 <= 3.5.1.22 - Missing Authorization to Limited File Upload
medium
The Smart Slider 3 plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the upload function in all versions up to, and including, 3.5.1.22. This makes it possible for authenticated attackers, with contributor-level access and above, to upload files, including SVG...
- CVSS:
- 6.4
- Affected:
- up to 3.5.1.22
- Fixed in:
- 3.5.1.23
- Disclosed:
- Apr 12, 2024
CVE-2024-3027 on NVD →
Smart Slider 3 [smart-slider-3] < 3.5.1.11
unknown
[en] Deserialization of Untrusted Data vulnerability in Nextend Smart Slider 3.This issue affects Smart Slider 3: from n/a through 3.5.1.9.
- Affected:
- up to 3.5.1.11
- Fixed in:
- 3.5.1.11
- Disclosed:
- Jan 19, 2024
CVE-2022-45845 on NVD →
Smart Slider 3 [smart-slider-3] < 3.5.1.14
unknown
[en] The Smart Slider 3 WordPress plugin before 3.5.1.14 does not properly validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks
- Affected:
- up to 3.5.1.14
- Fixed in:
- 3.5.1.14
- Disclosed:
- Mar 27, 2023
CVE-2023-0660 on NVD →
Smart Slider 3 [smart-slider-3] < 3.5.1.11
unknown
[en] Auth. (contributor+) Stored Cross-Site Scripting vulnerability in Nextend Smart Slider 3 plugin <= 3.5.1.9 versions.
- Affected:
- up to 3.5.1.11
- Fixed in:
- 3.5.1.11
- Disclosed:
- Mar 23, 2023
CVE-2022-45843 on NVD →
Smart Slider 3 <= 3.5.1.13 - Authenticated (Contributor+) Stored Cross-Site Scripting
medium
The Smart Slider 3 plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's shortcode(s) in versions up to, and including, 3.5.1.13 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers with contributor-level...
- CVSS:
- 6.4
- Affected:
- up to 3.5.1.13
- Fixed in:
- 3.5.1.14
- Disclosed:
- Feb 28, 2023
CVE-2023-0660 on NVD →
Smart Slider 3 <= 3.5.1.9 - Authenticated (Contributor+) PHP Object Injection
high
The Smart Slider 3 plugin for WordPress is vulnerable to PHP Object Injection in versions up to, and including, 3.5.1.9 via deserialization of untrusted input. This allows contributor-level attackers to inject a PHP Object. No POP chain is present in the vulnerable plugin. If a POP chain is present via an additional p...
- CVSS:
- 8.8
- Affected:
- up to 3.5.1.9
- Fixed in:
- 3.5.1.11
- Disclosed:
- Nov 23, 2022
CVE-2022-45845 on NVD →
Smart Slider 3 <= 3.5.1.9 - Authenticated (Contributor+) Stored Cross-Site Scripting
medium
The Smart Slider 3 plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 3.5.1.9 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level permissions and above, to inject arbitrary web scripts in...
- CVSS:
- 6.4
- Affected:
- up to 3.5.1.9
- Fixed in:
- 3.5.1.11
- Disclosed:
- Nov 23, 2022
CVE-2022-45843 on NVD →
Smart Slider 3 [smart-slider-3] < 3.5.1.11
unknown
[en] The Smart Slider 3 WordPress plugin before 3.5.1.11 unserialises the content of an imported file, which could lead to PHP object injection issues when a user import (intentionally or not) a malicious file, and a suitable gadget chain is present on the site.
- Affected:
- up to 3.5.1.11
- Fixed in:
- 3.5.1.11
- Disclosed:
- Oct 31, 2022
CVE-2022-3357 on NVD →
Smart Slider 3 <= 3.5.1.9 - PHP Object Injection
high
The Smart Slider 3 plugin for WordPress is vulnerable to PHP Object Injection in versions up to, and including, 3.5.1.9 via deserialization of untrusted input when importing a file. This allows administrator-level attackers to inject a PHP Object. No POP chain is present in the vulnerable plugin. If a POP chain is pre...
- CVSS:
- 7.2
- Affected:
- up to 3.5.1.9
- Fixed in:
- 3.5.1.11
- Disclosed:
- Oct 10, 2022
CVE-2022-3357 on NVD →
Smart Slider 3 [smart-slider-3] < 3.5.0.9
unknown
[en] The Smart Slider 3 Free and pro WordPress plugins before 3.5.0.9 did not sanitise the Project Name before outputting it back in the page, leading to a Stored Cross-Site Scripting issue. By default, only administrator users could access the affected functionality, limiting the exploitability of the vulnerability. H...
- Affected:
- up to 3.5.0.9
- Fixed in:
- 3.5.0.9
- Disclosed:
- Jun 14, 2021
CVE-2021-24382 on NVD →
Smart Slider 3 <= 3.5.0.8 - Authenticated Stored Cross-Site Scripting
medium
The Smart Slider 3 Free and pro WordPress plugins before 3.5.0.9 did not sanitise the Project Name before outputting it back in the page, leading to a Stored Cross-Site Scripting issue. By default, only administrator users could access the affected functionality, limiting the exploitability of the vulnerability. Howeve...
- CVSS:
- 5.4
- Affected:
- up to 3.5.0.9
- Fixed in:
- 3.5.0.9
- Disclosed:
- Jun 7, 2021
CVE-2021-24382 on NVD →
Smart Slider 3 [smart-slider-3] < 3.5.1.29
unknown
- Affected:
- up to 3.5.1.29
- Fixed in:
- 3.5.1.29
CVE-2025-6348 on NVD →
Protect your WordPress site
Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.
Scan your site free
← Back to the vulnerability database