CVE-2026-3098
CVSS 6.5 MEDIUM: the Smart Slider 3 plugin for WordPress is vulnerable to Arbitrary File Read in all versions up to, and including, 3.5.1.33 via the 'actionExportAll' function. EPSS 0.4% (33º percentile).
Vulnerabilità ed exploit · Attacco ad app web
Una falla di file-read in Smart Slider 3 consente a utenti autenticati con ruolo subscriber di leggere file arbitrari sul server. Il bug interessa le versioni fino alla 3.5.1.33 e oltre 800.000 siti.
1 fonte · 29 mar
CVSS 6.5 MEDIUM: the Smart Slider 3 plugin for WordPress is vulnerable to Arbitrary File Read in all versions up to, and including, 3.5.1.33 via the 'actionExportAll' function. EPSS 0.4% (33º percentile).
BleepingComputer
File read flaw in Smart Slider plugin impacts 500K WordPress sites
A vulnerability in the Smart Slider 3 WordPress plugin, active on more than 800,000 websites, can be exploited to allow subscriber-level users access to arbitrary files on the server.
originalePart of the PlainSec briefing for 2026-03-29
Every edition of this story: Smart Slider: utenti subscriber possono leggere file sensibili