A file-read vulnerability in the Smart Slider 3 WordPress plugin could let authenticated users with only subscriber-level access read arbitrary files from the server, including wp-config.php, on more than 500,000 likely unpatched sites. The flaw, tracked as CVE-2026-3098, affects all versions through 3.5.1.33 and stems from missing capability checks and insufficient file validation in the plugin’s AJAX export functionality.
Researcher Dmitrii Ignatyev reported the issue, which was validated by Wordfence before developer Nextendweb released a fix in Smart Slider 3 3.5.1.34. Security reporting said there was no evidence of active exploitation at publication time, but successful attacks could expose database credentials, cryptographic keys, and WordPress salt values, creating a path to broader site compromise.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
4 events from the most recent confirmed update back to the earliest known activity.
By March 29-30, public reporting disclosed CVE-2026-3098 and warned that although Smart Slider 3 is active on more than 800,000 sites, at least 500,000 WordPress sites likely remained vulnerable because they had not yet updated. Reports said there was no evidence of active exploitation at the time, but successful attacks could expose database credentials, cryptographic keys, and WordPress salts, enabling broader site compromise.
Security researcher Dmitrii Ignatyev discovered an arbitrary file-read vulnerability in the Smart Slider 3 WordPress plugin and reported it to Wordfence, which validated the issue and notified plugin developer Nextendweb. The flaw was later tracked as CVE-2026-3098 and affects versions through 3.5.1.33.
On March 24, Nextendweb released Smart Slider 3 version 3.5.1.34 to fix the authenticated arbitrary file-read vulnerability caused by missing capability checks and insufficient file validation in AJAX export functionality. The bug could allow subscriber-level users to read sensitive files such as wp-config.php.
On 2026-02-24, Wordfence rolled out firewall protections for paid users against the Smart Slider 3 arbitrary file-read flaw later tracked as CVE-2026-3098. The mitigation followed researcher Dmitrii Ignatyev's report through the Wordfence Bug Bounty Program on February 23.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
3 references tracked. Mallory keeps watching after this page renders.
cybersecuritynews.com
Open sourcescworld.com
Open sourcebleepingcomputer.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.