A critical vulnerability in the Smart Slider 3 WordPress plugin exposed more than 800,000 websites to arbitrary file read attacks, allowing authenticated users to access sensitive files on affected servers. The flaw, tracked as CVE-2026-3098 and rated CVSS 6.5, affects version 3.5.1.33 and earlier of the widely used plugin.
Researchers said the issue stems from the plugin’s actionExportAll() function, which does not properly validate the format and source of requested files. That weakness lets even low-privileged users, including subscribers, read arbitrary files such as wp-config.php, creating a risk of credential theft and broader compromise. Defenders were urged to update immediately to Smart Slider 3 3.5.1.34 or later.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
2 events from the most recent confirmed update back to the earliest known activity.
The references state that the recommended mitigation for CVE-2026-3098 is to update Smart Slider 3 immediately to version 3.5.1.34 or later. More than 800,000 WordPress sites were described as affected by the vulnerable plugin versions.
Security researchers warned about CVE-2026-3098, an arbitrary file read flaw in the WordPress Smart Slider 3 plugin affecting version 3.5.1.33 and earlier. The issue allows any authenticated user, including subscribers, to read arbitrary server files such as wp-config.php due to improper validation in the actionExportAll() function.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.