Backdoored Smart Slider Update Delivered via Official Channel

A compromised update server pushed a backdoored Smart Slider 3 Pro version 3.5.1.35 to WordPress sites, delivering a remote access toolkit that standard patching misses. The malicious update enabled attackers to execute system commands and PHP code remotely, create hidden admin accounts, and maintain persistent access. Sites that updated within a six-hour window on April 7, 2026, are at risk of ongoing compromise despite applying the update. Nextend's update infrastructure was breached, allowing an unauthorized party to distribute a fully attacker-authored build through the official update channel. This affected Smart Slider 3 Pro, a widely used WordPress plugin with over 800,000 active installations. The backdoor included pre-authenticated remote code execution via HTTP headers and stealth mechanisms to evade detection by legitimate administrators. This incident shows that even trusted update channels can be weaponized to deliver persistent backdoors. The risk persists beyond patching because attackers can create hidden accounts and execute arbitrary code, making cleanup and detection more complex. This attack highlights the need to verify plugin integrity and monitor for unusual administrative activity after updates.

Part of the PlainSec briefing for 2026-04-11

Sources