CVE-2026-3098
CVSS 6.5 MEDIUM: the Smart Slider 3 plugin for WordPress is vulnerable to Arbitrary File Read in all versions up to, and including, 3.5.1.33 via the 'actionExportAll' function. EPSS 0.5% (38th percentile).
Vulnerabilities & Exploits · Web App Attack
Smart Slider 3 plugin contains an authenticated file-read flaw allowing low-privilege subscribers to download arbitrary server files. The bug affects all versions through 3.5.1.33 and can expose wp-config.php and other sensitive files on 800,000+ WordPress sites; tracked as CVE-2026-3098 and rated medium because it requires authentication.
1 source · Mar 29
CVSS 6.5 MEDIUM: the Smart Slider 3 plugin for WordPress is vulnerable to Arbitrary File Read in all versions up to, and including, 3.5.1.33 via the 'actionExportAll' function. EPSS 0.5% (38th percentile).
BleepingComputer
File read flaw in Smart Slider plugin impacts 500K WordPress sites
A vulnerability in the Smart Slider 3 WordPress plugin, active on more than 800,000 websites, can be exploited to allow subscriber-level users access to arbitrary files on the server.
originalPart of the PlainSec briefing for 2026-03-30
Every edition of this story: Smart Slider Vulnerability Lets Subscribers Read Server Files