What this page helps you verify fast
This hub clusters tracked records for Smart Slider 3 so operators can confirm whether a disclosed issue maps to the installed slug, version range, and patch path.
Review known vulnerability records for the WordPress plugin Smart Slider 3 (`smart-slider-3`), including severity, CVE references, affected versions, and patch status.
Recent tracked CVEs on this page include CVE-2026-9197, CVE-2026-4065 and CVE-2026-3098, so operators can jump from disclosure to patch validation without scanning the full feed first.
Pair this plugin vulnerability hub with practical WordPress hardening, scanner, and patch workflow guidance.
Review patch cadence, privileged access, XML-RPC exposure, backups, and monitoring controls.
Use ownership, update testing, least privilege, and removal criteria to reduce plugin risk.
Compare scanner coverage for plugin CVEs, version detection, alert noise, and remediation workflow.
Use the hub as a decision layer before opening individual records: confirm whether the issue has a CVE, whether a fixed version exists, and whether the affected range overlaps production installs.
Affected range: Versions up to 3.5.1.9. Fixed version: 3.5.1.11.
Affected range: Versions up to 3.5.1.9. Fixed version: 3.5.1.11.
Affected range: Versions up to 3.5.1.33. Fixed version: 3.5.1.34.
Affected range: Versions up to 3.5.1.22. Fixed version: 3.5.1.23.
Start with the highest-signal CVE records for this WordPress plugin before scanning the full vulnerability feed.
| Tracked CVE | Issue Type | Affected Versions | Fixed Version | CVSS |
|---|---|---|---|---|
|
CVE-2022-45845
Smart Slider 3 <= 3.5.1.9 - Authenticated (Contributor+) PHP Object Injection
|
Vulnerability | Versions up to 3.5.1.9 | 3.5.1.11 | CVSS 8.8 |
|
CVE-2022-3357
Smart Slider 3 <= 3.5.1.9 - PHP Object Injection
|
Vulnerability | Versions up to 3.5.1.9 | 3.5.1.11 | CVSS 7.2 |
|
CVE-2026-3098
Smart Slider 3 <= 3.5.1.33 - Authenticated (Subscriber+) Arbitrary File Read via act...
|
Vulnerability | Versions up to 3.5.1.33 | 3.5.1.34 | CVSS 6.5 |
|
CVE-2024-3027
Smart Slider 3 <= 3.5.1.22 - Missing Authorization to Limited File Upload
|
File Upload | Versions up to 3.5.1.22 | 3.5.1.23 | CVSS 6.4 |
|
CVE-2023-0660
Smart Slider 3 <= 3.5.1.13 - Authenticated (Contributor+) Stored Cross-Site Scriptin...
|
Stored Cross-Site Scripting | Versions up to 3.5.1.13 | 3.5.1.14 | CVSS 6.4 |
|
CVE-2022-45843
Smart Slider 3 <= 3.5.1.9 - Authenticated (Contributor+) Stored Cross-Site Scripting
|
Stored Cross-Site Scripting | Versions up to 3.5.1.9 | 3.5.1.11 | CVSS 6.4 |
|
CVE-2026-4065
Smart Slider 3 <= 3.5.1.33 - Missing Authorization to Authenticated (Contributor+) S...
|
Vulnerability | Versions up to 3.5.1.33 | 3.5.1.34 | CVSS 5.4 |
|
CVE-2021-24382
Smart Slider 3 <= 3.5.0.8 - Authenticated Stored Cross-Site Scripting
|
Stored Cross-Site Scripting | Versions before 3.5.0.9 | 3.5.0.9 | CVSS 5.4 |
Smart Slider 3 <= 3.5.1.9 - Authenticated (Contributor+) PHP Object Injection
Smart Slider 3 <= 3.5.1.9 - PHP Object Injection
Smart Slider 3 <= 3.5.1.33 - Authenticated (Subscriber+) Arbitrary File Read via actionExportAll
Smart Slider 3 <= 3.5.1.22 - Missing Authorization to Limited File Upload
Smart Slider 3 <= 3.5.1.13 - Authenticated (Contributor+) Stored Cross-Site Scripting
Smart Slider 3 <= 3.5.1.9 - Authenticated (Contributor+) Stored Cross-Site Scripting
Smart Slider 3 <= 3.5.1.33 - Missing Authorization to Authenticated (Contributor+) Slider Data Read and Image Record Manipulation
Smart Slider 3 <= 3.5.0.8 - Authenticated Stored Cross-Site Scripting
This hub clusters tracked records for Smart Slider 3 so operators can confirm whether a disclosed issue maps to the installed slug, version range, and patch path.
These recent records surface the CVE strings, patch cues, and direct report links most operators need first.
The Smart Slider 3 plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 3.5.1.36 via the replaceHTMLImage function. This makes it possible for auth...
The Smart Slider 3 plugin for WordPress is vulnerable to unauthorized access and modification of data due to missing capability checks on multiple wp_ajax_smart-slider3 controller actions in...
The Smart Slider 3 plugin for WordPress is vulnerable to Arbitrary File Read in all versions up to, and including, 3.5.1.33 via the 'actionExportAll' function. This makes it possible for aut...
Sorted by latest disclosure date so newly published issues surface first.
The Smart Slider 3 plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 3.5.1.36 via the replaceHTMLImage function. This makes it possible for authenticated attackers, with administrator-level access and above, to read the contents of ar...
The Smart Slider 3 plugin for WordPress is vulnerable to unauthorized access and modification of data due to missing capability checks on multiple wp_ajax_smart-slider3 controller actions in all versions up to, and including, 3.5.1.33. The display_admin_ajax() method does not cal...
The Smart Slider 3 plugin for WordPress is vulnerable to Arbitrary File Read in all versions up to, and including, 3.5.1.33 via the 'actionExportAll' function. This makes it possible for authenticated attackers, with Subscriber-level access and above, to read the contents of arbi...
The Smart Slider 3 plugin for WordPress is vulnerable to time-based SQL Injection via the ‘sliderid’ parameter in all versions up to, and including, 3.5.1.28 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query....
The Smart Slider 3 plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the upload function in all versions up to, and including, 3.5.1.22. This makes it possible for authenticated attackers, with contributor-level access an...
The Smart Slider 3 plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's shortcode(s) in versions up to, and including, 3.5.1.13 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authent...
The Smart Slider 3 plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 3.5.1.9 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level permissions and ab...
The Smart Slider 3 plugin for WordPress is vulnerable to PHP Object Injection in versions up to, and including, 3.5.1.9 via deserialization of untrusted input. This allows contributor-level attackers to inject a PHP Object. No POP chain is present in the vulnerable plugin. If a P...
The Smart Slider 3 plugin for WordPress is vulnerable to PHP Object Injection in versions up to, and including, 3.5.1.9 via deserialization of untrusted input when importing a file. This allows administrator-level attackers to inject a PHP Object. No POP chain is present in the v...
The Smart Slider 3 Free and pro WordPress plugins before 3.5.0.9 did not sanitise the Project Name before outputting it back in the page, leading to a Stored Cross-Site Scripting issue. By default, only administrator users could access the affected functionality, limiting the exp...