CVE-2026-3098: Smart Slider 3 <= 3.5.1.33 - Authenticated (Subscriber+) Arbitrary File Read via actionExportAll
The Smart Slider 3 plugin for WordPress is vulnerable to Arbitrary File Read in all versions up to, and including, 3.5.1.33 via the 'actionExportAll' function. This makes it possible for authenticated attackers, with Subscriber-level access and above, to read the contents of arbitrary files on the server, which can contain sensitive information.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-3098?
CVE-2026-3098 is considered a high severity vulnerability due to its potential for arbitrary file read by authenticated users.
How do I fix CVE-2026-3098?
To address CVE-2026-3098, update the Smart Slider 3 plugin to version 3.5.1.34 or later.
Who is affected by CVE-2026-3098?
CVE-2026-3098 affects all installations of Smart Slider 3 plugin up to and including version 3.5.1.33.
What type of vulnerability is CVE-2026-3098?
CVE-2026-3098 is classified as an Arbitrary File Read vulnerability.
Can CVE-2026-3098 be exploited remotely?
CVE-2026-3098 requires authentication, so it can only be exploited by authenticated users with appropriate permissions.