A new vulnerability in the popular WordPress plugin Smart Slider 3 has caused widespread concern in the cybersecurity community, affecting more than 800,000 websites worldwide. The issue allows even low-level users, such as simple subscribers, to gain access to sensitive server files, posing serious risks to data security and website integrity.

Smart Slider 3: How the CVE-2026-3098 vulnerability works
The vulnerability, reported as CVE-2026-3098 , is located in the plugin's data export mechanism and affects all versions up to 3.5.1.33. The core issue arises from the lack of permission checks in AJAX export functions , allowing any user with a valid login to execute them . This means that even users with limited permissions can exploit the function to gain access to files that should normally be protected.
Access to critical files and complete breach
Most worryingly, the vulnerability allows the reading of critical files such as wp-config.php. This file contains database credentials, as well as keys and salts used for WordPress security. If this data is leaked, an attacker could gain complete control of the site, steal user information, or even install malware.
See also: SQLi vulnerability in Ally plugin affects 250k+ WordPress sites
The technical background of the problem
According to Defiant, the vulnerability is due to the “actionExportAll” function, which does not apply checks on either the file type or its origin. This allows the export of not only multimedia, but also PHP files or other sensitive data from the server. Despite the existence of a nonce mechanism, the protection proves to be insufficient, as it can be exploited by already authenticated users.

The spread of the problem and the delayed updates
Although the issue was reported in February and confirmed by Wordfence, the fix was only released in late March with version 3.5.1.34. However, data shows that at least 500,000 websites are still using vulnerable versions. This fact highlights a perennial problem in the WordPress ecosystem: the delay in installing security updates.
Why subscribers are a threat in this case
Traditionally, subscriber accounts have been considered low-risk, as they have limited privileges. However, this vulnerability challenges this assumption. On websites that allow user registration—such as e-shops, forums, or subscription content platforms—an attacker can easily create an account and exploit the vulnerability without requiring advanced privileges.
See also: WordPress: Vulnerability in the User Registration & Membership plugin
The Bigger Picture: Plugins as a Weak Link
This incident highlights once again that plugins are one of the most vulnerable links in the WordPress ecosystem. Despite the functionality they offer, they often introduce additional attack surfaces, especially when are not followed strict security standards during their development. With thousands of plugins available, managing risk is becoming increasingly difficult for website administrators.
What website administrators should do immediately
An immediate upgrade to version 3.5.1.34 is considered imperative. In addition, administrators should review logs for suspicious activity, restrict user access where possible, and implement additional security measures, such as application firewalls and intrusion detection systems . Prevention remains the most effective strategy, especially in high-traffic environments.
See also: Advanced Custom Fields: Extended WordPress – Serious vulnerability

Another bell for WordPress security
Although the CVE-2026-3098 vulnerability has not yet been widely exploited in attacks, experts warn that this could change at any time. In a digital world where attacks are automated and spread rapidly, a delay in responding can have serious consequences. For website owners, the message is clear: security is not optional, but a basic requirement for survival on the modern internet.
Source: www.bleepingcomputer.com
🔒 Protect your privacy with Proton VPN
Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.
- ✔ No-logs, based in Switzerland (except 14-Eyes)
- ✔ NetShield: blocks ads, trackers & malicious domains
- ✔ Covers all devices — free version available
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
