Junglewise Threat Intelligence

CVE-2026-9197: Nextend Smart Slider 3 directory traversal in replaceHTMLImage

CVE-2026-9197 · Severity: medium · CVSS 4.9 · Published 2026-06-06

Technologies: Nextend Smart Slider 3. Vendors: Nextend.

Executive brief

Smart Slider 3, a popular WordPress plugin used for creating visual sliders, contains a security flaw that allows high-level administrators to access files they should not be able to see. By exploiting this vulnerability, an attacker with administrative credentials could read sensitive configuration files or other private data stored on the web server. This could lead to further compromise of the website or the underlying server infrastructure.

Technical details

A directory traversal vulnerability (CWE-22) exists in the Smart Slider 3 plugin for WordPress due to insufficient input validation in the 'replaceHTMLImage' function. The flaw is located within the administrative controller and backup export components of the plugin. An authenticated attacker with 'Administrator' or higher privileges can exploit this by submitting crafted requests that use 'dot-dot-slash' (../) sequences to navigate outside the intended directory. This allows for the unauthorized reading of arbitrary files on the server. The vulnerability is addressed in versions following 3.5.1.36.

Affected products

  • Nextend Smart Slider 3 Up to, and including, 3.5.1.36

Timeline

  • 2026-06-06: disclosed
  • 2026-06-06: advisory

References

Related threats