AppSec · 158 days ago
A compromised update server pushed a backdoored Smart Slider 3 Pro version 3.5.1.35 to WordPress sites, delivering a remote access toolkit that standard patching misses. The malicious update enabled attackers to execute system commands and PHP code remotely, create hidden admin accounts, and maintain persistent access. Sites that updated within a six-hour window on April 7, 2026, are at risk of ongoing compromise despite applying the update.
Nextend's update infrastructure was breached, allowing an unauthorized party to distribute a fully attacker-authored build through the official update channel. This affected Smart Slider 3 Pro, a widely used WordPress plugin with over 800,000 active installations. The backdoor included pre-authenticated remote code execution via HTTP headers and stealth mechanisms to evade detection by legitimate administrators.
This incident shows that even trusted update channels can be weaponized to deliver persistent backdoors. The risk persists beyond patching because attackers can create hidden accounts and execute arbitrary code, making cleanup and detection more complex. This attack highlights the need to verify plugin integrity and monitor for unusual administrative activity after updates.
2 sources covering this story
Backdoored Smart Slider 3 Pro Update Distributed via Compromised Nextend Servers
Backdoored Smart Slider 3 Pro v3.5.1.35 update distributed for 6 hours via compromised infrastructure, enabling RCE and data theft.
Smart Slider updates hijacked to push malicious WordPress, Joomla versions
Hackers hijacked the update system for the Smart Slider 3 Pro plugin for WordPress and Joomla, and pushed a malicious version with multiple backdoors.
Part of the PlainSec briefing for 2026-04-11