Skip to main content
Live Webinar with SANS (June 25)— Agentic CTI Automation for Fun & ProfitRegister Free
Mallory
Back to intelligence
internet-facing-service-vulnerabilitywidely-deployed-product-advisorycredential-access-method

Smart Slider 3 File-Read Flaw Exposes WordPress Secrets on 500,000 Sites

Updated 3mo agoFirst seen Mar 29, 20263 sources

A file-read vulnerability in the Smart Slider 3 WordPress plugin could let authenticated users with only subscriber-level access read arbitrary files from the server, including wp-config.php, on more than 500,000 likely unpatched sites. The flaw, tracked as CVE-2026-3098, affects all versions through 3.5.1.33 and stems from missing capability checks and insufficient file validation in the plugin’s AJAX export functionality.

Researcher Dmitrii Ignatyev reported the issue, which was validated by Wordfence before developer Nextendweb released a fix in Smart Slider 3 3.5.1.34. Security reporting said there was no evidence of active exploitation at publication time, but successful attacks could expose database credentials, cryptographic keys, and WordPress salt values, creating a path to broader site compromise.

Share:
Smart Slider 3 File-Read Flaw Exposes WordPress Secrets on 500,000 Sites
Stay ahead

Get ahead of threats like this

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.

EVENT TIMELINE

How this story unfolded

4 events from the most recent confirmed update back to the earliest known activity.

4 EVENTS
Mar 29, 20263mo ago

Public disclosure warns hundreds of thousands of WordPress sites remain exposed

By March 29-30, public reporting disclosed CVE-2026-3098 and warned that although Smart Slider 3 is active on more than 800,000 sites, at least 500,000 WordPress sites likely remained vulnerable because they had not yet updated. Reports said there was no evidence of active exploitation at the time, but successful attacks could expose database credentials, cryptographic keys, and WordPress salts, enabling broader site compromise.

Researcher discovers and reports Smart Slider 3 file-read flaw

Security researcher Dmitrii Ignatyev discovered an arbitrary file-read vulnerability in the Smart Slider 3 WordPress plugin and reported it to Wordfence, which validated the issue and notified plugin developer Nextendweb. The flaw was later tracked as CVE-2026-3098 and affects versions through 3.5.1.33.

Mar 24, 20263mo ago

Nextendweb releases Smart Slider 3 version 3.5.1.34 to patch CVE-2026-3098

On March 24, Nextendweb released Smart Slider 3 version 3.5.1.34 to fix the authenticated arbitrary file-read vulnerability caused by missing capability checks and insufficient file validation in AJAX export functionality. The bug could allow subscriber-level users to read sensitive files such as wp-config.php.

Feb 24, 20264mo ago

Wordfence deploys firewall protection for CVE-2026-3098

On 2026-02-24, Wordfence rolled out firewall protections for paid users against the Smart Slider 3 arbitrary file-read flaw later tracked as CVE-2026-3098. The mitigation followed researcher Dmitrii Ignatyev's report through the Wordfence Bug Bounty Program on February 23.

WordPress Plugin Vulnerability Exposes Sensitive Data from 800,000+ Sites
LINKED ENTITIES

Related entities

Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.

12 LINKEDOpen in app
Affected products
3 linked
WordpressWordfenceSmart Slider 3
Organizations
8 linked
WordfenceLinkedinXGoogleNextendWordpressNextendwebBleepingComputer
The operational view lives in Mallory

See the full picture, correlated to your attack surface.

This page covers what’s public. Mallory adds the parts that aren’t — which of your assets are affected, which threat actors are using it right now, which detections to deploy, and what to do next.
Exposure mapping

Map indicators from this story to your assets and identify affected systems in minutes.

Threat actor evidence

Every observed campaign, victim, and pivot linked to actors named in this story.

Associated malware

Malware, exploits, and IOCs connected to the activity described here.

Detection signatures

YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.

Scheduled alerts

Get matching new stories delivered to your team as they break — not the next morning.

AI threads

Ask questions about this story and take action on the answers.