A vulnerability in the Smart Slider 3 WordPress plugin, active on more than 800,000 websites, can be exploited to allow subscriber-level users access to arbitrary files on the server. An authenticated attacker could use it to access sensitive files, such as wp-config.php, which includes database credentials, keys, and salt data, creating the risk for user data theft and complete website takeover. Smart Slider 3 is one of the most popular WordPress plugins for creating and managing image sliders and content carousels. It offers an easy-to-use drag-and-drop editor and a rich set of templates to choose from. The security issue, tracked as CVE-2026-3098, was discovered and reported by researcher Dmitrii Ignatyev and impacts all versions of the Smart Slider 3 plugin through 3.5.1.33. It received a medium severity score due to requiring authentication. However, this only limits the impact to websites with membership or subscription options, a feature that is common on many platforms these days. The vulnerability stems from missing capability checks in the plugin’s AJAX export actions. This allows any authenticated user, including subscribers, to invoke them. According to researchers at WordPress security company Defiant, the developer of the Wordfence security plugin, the 'actionExportAll' function lacks file type and source validation, thus allowing arbitrary server files to be read and added to the export archive. The presence of a nonce does not prevent abuse because it can be ...
File read flaw in Smart Slider plugin impacts 500K WordPress sites
BleepingComputer
·Bill Toulas
·Published Mar 29, 2026
·Updated
Affected Software
1 affected component
Nextendweb Smart Slider 3<=3.5.1.33
Frequently Asked Questions
1
What is the main topic of this article?
The article discusses a security vulnerability in the Smart Slider 3 plugin for WordPress that affects over 500,000 websites.
2
What security implications are discussed?
The vulnerability allows authenticated users with subscriber-level access to read arbitrary files on the server, posing a risk to sensitive information.
3
What products or software are affected?
The affected product is the Smart Slider 3 plugin developed by Nextendweb, specifically versions up to 3.5.1.33.
4
How many WordPress sites are impacted by this vulnerability?
The vulnerability potentially impacts over 800,000 WordPress sites using the Smart Slider 3 plugin.
5
What can attackers do with this vulnerability?
Attackers could exploit the flaw to access sensitive files on the server if they have subscriber-level authentication.