Vulnerabilities & Exploits · Web App Attack

Smart Slider Vulnerability Lets Subscribers Read Server Files

A file-read flaw in the Smart Slider 3 WordPress plugin allows authenticated subscriber-level users to read arbitrary server files. The bug affects versions through 3.5.1.33 on over 800,000 sites and can expose wp-config.php; tracked as CVE-2026-3098 and rated medium due to required authentication.

1 source · Mar 29

CVE-2026-3098

NVD KEV

CVSS 6.5 MEDIUM: the Smart Slider 3 plugin for WordPress is vulnerable to Arbitrary File Read in all versions up to, and including, 3.5.1.33 via the 'actionExportAll' function. EPSS 0.5% (38th percentile).

Timeline

Sources

Part of the PlainSec briefing for 2026-03-29

Every edition of this story: Smart Slider Vulnerability Lets Subscribers Read Server Files

More from today