Smart Slider Vulnerability Lets Subscribers Read Server Files

Smart Slider 3 plugin contains an authenticated file-read flaw allowing low-privilege subscribers to download arbitrary server files. The bug affects all versions through 3.5.1.33 and can expose wp-config.php and other sensitive files on 800,000+ WordPress sites; tracked as CVE-2026-3098 and rated medium because it requires authentication.

Part of the PlainSec briefing for 2026-03-30

Sources