Around 500,000 WordPress Sites May Be at Risk Due to Crucial Plugin Security Flaws – Here’s What We Know


  • Smart Slider 3 WordPress plugin (used on 800,000 sites) has an arbitrary file reading flaw that allows access to sensitive server files
  • Vulnerability allowed even low-privileged accounts to exfiltrate credentials and configuration data via AJAX export functions
  • Patch released in version 3.5.1.34, but nearly 500,000 sites remain exposed; users are encouraged to update immediately

A popular WordPress plugin used by hundreds of thousands of websites reportedly contained a vulnerability that allowed threat actors to steal sensitive information such as login credentials, experts have warned.

Currently active on more than 800,000 websites, Smart Slider 3 allows users to create responsive, custom sliders and visual content blocks without coding.

Leave a Comment

Your email address will not be published. Required fields are marked *

Scroll to Top