Extension WordPress

Vulnérabilités Smart Slider 3

Cette page rassemble les failles publiées pour Smart Slider 3, leurs plages de versions affectées et les correctifs signalés dans la base locale.

11Vulnérabilités
0Critiques
11Avec correctif
8,8CVSS maximal

Historique de sécurité

CVE et vulnérabilités de Smart Slider 3

11 fiches

CVE-2026-12385 Moyenne · 4,3
Smart Slider 3

Smart Slider 3 <= 3.5.1.37 – Missing Authorization to Authenticated (Contributor+) Sensitive Information Exposure via WP_Query Parameter Injection via 'keyword' Parameter

The Smart Slider 3 plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 3.5.1.37 via the 'keyword' parameter. This makes it possible for authenticated attackers, with contributor-level access and above, to…

Versions affectées

*-3.5.1.37

Correctif

3.5.1.38

Publication

13/07/2026

CVE-2026-9197 Moyenne · 4,9
Smart Slider 3

Smart Slider 3 <= 3.5.1.36 – Authenticated (Administrator+) Path Traversal to Arbitrary File Read via 'src'/'srcset' Attribute in HTML Export

The Smart Slider 3 plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 3.5.1.36 via the replaceHTMLImage function. This makes it possible for authenticated attackers, with administrator-level access and above, to read…

Versions affectées

*-3.5.1.36

Correctif

3.5.1.37

Publication

05/06/2026

CVE-2026-4065 Moyenne · 5,4
Smart Slider 3

Smart Slider 3 <= 3.5.1.33 – Missing Authorization to Authenticated (Contributor+) Slider Data Read and Image Record Manipulation

The Smart Slider 3 plugin for WordPress is vulnerable to unauthorized access and modification of data due to missing capability checks on multiple wp_ajax_smart-slider3 controller actions in all versions up to, and including, 3.5.1.33. The display_admin_ajax() method does…

Versions affectées

*-3.5.1.33

Correctif

3.5.1.34

Publication

07/04/2026

CVE-2026-3098 Moyenne · 6,5
Smart Slider 3

Smart Slider 3 <= 3.5.1.33 – Authenticated (Subscriber+) Arbitrary File Read via actionExportAll

The Smart Slider 3 plugin for WordPress is vulnerable to Arbitrary File Read in all versions up to, and including, 3.5.1.33 via the 'actionExportAll' function. This makes it possible for authenticated attackers, with Subscriber-level access and above, to…

Versions affectées

*-3.5.1.33

Correctif

3.5.1.34

Publication

26/03/2026

CVE-2022-45843 Moyenne · 6,4
Smart Slider 3

Smart Slider 3 <= 3.5.1.9 – Authenticated (Contributor+) Stored Cross-Site Scripting

The Smart Slider 3 plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 3.5.1.9 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level permissions…

Versions affectées

*-3.5.1.9

Correctif

3.5.1.11

Publication

23/11/2022

WP Commander

Rechercher dans toute la base WordPress

Utilisez la recherche globale pour retrouver une extension, un thème, une CVE ou un identifiant de vulnérabilité.

Ouvrir le tableau des vulnérabilités