9.3 C
United Kingdom
Monday, March 30, 2026

Around 500,000 WordPress websites could be at risk from crucial plugin security flaw — here’s what we know



  • Smart Slider 3 WordPress plugin (used on 800,000 sites) carried Arbitrary File Read flaw enabling access to sensitive server files
  • Vulnerability allowed even low-privileged accounts to exfiltrate credentials and configuration data via AJAX export functions
  • Patch released in version 3.5.1.34, but nearly 500K sites remain exposed; users urged to update immediately

A popular WordPress plugin used by hundreds of thousands of websites reportedly carried a vulnerability which allowed threat actors to steal sensitive information such as login credentials, experts have warned.

Smart Slider 3, which is currently active on more than 800,000 websites, allows users to create responsive, customizable sliders and visual content blocks without needing to code.



Related Articles

LEAVE A REPLY

Please enter your comment!
Please enter your name here

Latest Articles