Executive brief
Smart Slider 3, a popular WordPress plugin for creating visual sliders, contains a security flaw that allows users with low-level 'Contributor' accounts to view private content. An attacker could use this to read draft posts, private articles, and deleted content authored by site administrators or editors. This could lead to the exposure of sensitive business information or upcoming announcements before they are intended for public release.
Technical details
A sensitive information exposure vulnerability exists in Smart Slider 3 due to improper access controls on the 'keyword' parameter within its AJAX content handling. Authenticated attackers with at least 'Contributor' privileges can exploit this by obtaining a security nonce from the standard WordPress post-creation page. By supplying this nonce to the vulnerable component, an attacker can query and retrieve titles and excerpts for posts they do not have permission to view, including drafts and private posts from Administrators. The issue is addressed in versions following 3.5.1.37.
Affected products
- Nextendweb Smart Slider 3 up to, and including, 3.5.1.37
Timeline
- 2026-07-13: advisory
- 2026-07-13: disclosed
References
- https://plugins.trac.wordpress.org/browser/smart-slider-3/tags/3.5.1.37/Nextend/Framework/Content/ControllerAjaxContent.php
- https://plugins.trac.wordpress.org/browser/smart-slider-3/tags/3.5.1.37/Nextend/Framework/Content/ControllerAjaxContent.php
- https://plugins.trac.wordpress.org/browser/smart-slider-3/tags/3.5.1.37/Nextend/Framework/Content/WordPress/WordPressContent.php
- https://plugins.trac.wordpress.org/browser/smart-slider-3/tags/3.5.1.37/Nextend/Framework/Content/WordPress/WordPressContent.php
- https://plugins.trac.wordpress.org/browser/smart-slider-3/tags/3.5.1.37/Nextend/Framework/Form/WordPress/PlatformForm.php
- https://plugins.trac.wordpress.org/changeset/3599123/smart-slider-3
- https://www.wordfence.com/threat-intel/vulnerabilities/id/a782d975-74ce-4265-9312-435b3585a5c6?source=cve