CVE-2026-3098Patch

MEDIUMCVSS 6.5 · MEDIUM

Exploitation observed; activity peaked at 5 mentions and remains active

Immediate actions

  • Patch affected systems immediately
  • Assume compromise if assets are exposed

Recommended action window: Immediate (within 24h)

NVD description

The Smart Slider 3 plugin for WordPress is vulnerable to Arbitrary File Read in all versions up to, and including, 3.5.1.33 via the 'actionExportAll' function. This makes it possible for authenticated attackers, with Subscriber-level access and above, to read the contents of arbitrary files on the server, which can contain sensitive information.

4.3/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-862

Priority

MEDIUM

Exploitation

ACTIVE

PoC

NONE

Patch

AVAILABLE

Momentum

DECLINING

Threat summary

  • Active exploitation appears in 5 classified signals
  • Patch or workaround signal is available
  • 22 mentions across 10 observed days
  • Momentum state: declining

What's happening

  • Active exploitation reported across 5 signals
  • Patch or workaround mentioned in 8 signals
  • Technical details provided in 16 signals
  • Disclosure: 7 classified signals
  • General: 4 classified signals
  • Peaked 7d ago at 5 mentions (2026-03-29); latest day: 1
  • 22 total mentions across 10 days

Deep dive

Activity timeline22 mentions / 10d
01345Mentions · 2026-03-26: 2Mentions · 2026-03-27: 3Mentions · 2026-03-29: 5Mentions · 2026-03-30: 4Mentions · 2026-03-31: 2Mentions · 2026-04-02: 1Mentions · 2026-04-06: 2Mentions · 2026-04-07: 1Mentions · 2026-04-09: 1Mentions · 2026-04-12: 1Active Exploitation · 2026-03-29: 1Active Exploitation · 2026-03-30: 1Active Exploitation · 2026-04-06: 1Active Exploitation · 2026-04-09: 1Active Exploitation · 2026-04-12: 1Patch / Workaround · 2026-03-26: 2Patch / Workaround · 2026-03-29: 2Patch / Workaround · 2026-03-30: 1Patch / Workaround · 2026-03-31: 1Patch / Workaround · 2026-04-09: 1Patch / Workaround · 2026-04-12: 1Technical Details · 2026-03-26: 2Technical Details · 2026-03-27: 2Technical Details · 2026-03-29: 4Technical Details · 2026-03-30: 4Technical Details · 2026-03-31: 2Technical Details · 2026-04-06: 1Technical Details · 2026-04-09: 103-2603-2703-2903-3003-3104-0204-0604-0704-0904-12
Signal classification4 categories
Patch
731.8%
Disclosure
731.8%
General
418.2%
Active Exploitation
418.2%
Referenced assets15 URLs
Classification over time
DateTotalLabels
2026-03-262
Patch2
2026-03-273
Disclosure2General1
2026-03-295
Active Exploitation1Disclosure1General1Patch2
2026-03-304
Active Exploitation1Disclosure2Patch1
2026-03-312
Disclosure1Patch1
2026-04-021
General1
2026-04-062
Active Exploitation1Disclosure1
2026-04-071
General1
2026-04-091
Patch1
2026-04-121
Active Exploitation1
Full discourse20 posts
  • Teegra 🧝‍♀️𝕏@Teeegra
    Disclosure

    آسیب‌پذیری در افزونه محبوب وردپرس Smart Slider 3 که روی بیش از ۸۰۰ هزار وب‌سایت نصب شده! این نقص امنیتی با شناسه CVE-2026-3098 به کاربران با سطح دسترسی پایین مثل مشترک (subscriber) اجازه می‌دهد به فایل‌های دلخواه روی سرور دسترسی پیدا کنند از جمله فایل حساس wp-config.php که حاوی اطلاعات پایگاه داده است

    Post summary

    A new CVE (CVE-2026-3098) was disclosed for the Smart Slider 3 WordPress plugin, enabling low‑privilege users to read arbitrary files such as wp-config.php, potentially exposing database credentials.

    0001271.3K
    18.9K followersView on X
  • إبراهيم بوحيمد | Ibrahim Buhaimed@buhaimedi
    Patch

    🔴تستخدم إضافة Smart Slider 3 في ورد بريس ؟ حدث الإضافة فوراً لوجود تسمح بقراءه ملفات السيرفر 📍رقمها: CVE-2026-3098. 📍 تم اكتشافها من قبل الباحث: Dmitrii Ignatyev الإصدارات المصابة: كل الإصدارات حتى 3.5.1.33 مصابه بالثغره. 📍 أي مستخدم عادي يقدر يقرأ ملفات السيرفر الحساسة مثل ملف wp-config.php اللي فيه كلمات سر قاعدة البيانات والمفاتيح الأمنية. 📍 الشركة أصدرت تحديث 3.5.1.34 في 24 مارس. 📊 عدد المواقع المصابة: 500k

    Post summary

    CVE-2026-3098 in Smart Slider 3 allowed any user to read sensitive server files like wp-config.php; affected about 500k sites and was fixed with update 3.5.1.34.

    0111311.6K
    49.2K followersView on X
  • iototsecnews@iototsecnews
    Disclosure

    WordPress Smart Slider 3 の脆弱性 CVE-2026-3098 が FIX:インフラの重要情報が露出 https://iototsecnews.jp/2026/03/30/wordpress-plugin-flaw-exposes-sensitive-data-across-800000-sites/ WordPress プラグイン Smart Slider 3 に、深刻な脆弱性 CVE-2026-3098 が発見されました。この問題の原因は、プラグインのエクスポート機能において欠落している、 操作を実行するユーザーの権限を正しく確認する仕組みと、読み出すファイルの形式を制限するチェックの不備にあります。さらに深刻なのは、データを ZIP ファイルにまとめる際の不備です。本来は画像などのマルチメディア・ファイルだけを対象にすべきところ、ファイル形式の検証が全く行われていなかったため、システム上の任意のファイルをアーカイブに含めることが可能となっています。ご利用のチームは、ご注意ください。 #CVE20263098 #SmartSlider3 #Vulnerability #WordPress

    Post summary

    The post announces the discovery of CVE‑2026‑3098 in WordPress Smart Slider 3, detailing how flawed permission checks and unchecked file types permit arbitrary files to be archived and exposed; no PoC, exploit code, or patch is referenced.

    02110170
    483 followersView on X
  • kokumօtօ@__kokumoto
    Patch

    80万サイト以上が使用するWordPressのSmart Slider 3に任意ファイル読み込みの脆弱性。CVE-2026-3098。購読者以上のアクセス権を持つ後継者がactionExportAll関数経由でサーバ上の任意のファイルを取得可能。バージョン3.5.1.34で修正。 https://www.wordfence.com/blog/2026/03/800000-wordpress-sites-affected-by-arbitrary-file-read-vulnerability-in-smart-slider-3-wordpress-plugin/

    Post summary

    Smart Slider 3 for WordPress suffers an arbitrary file read vulnerability (CVE-2026-3098) that allows privileged users to read any server file via the actionExportAll function; the issue is fixed in version 3.5.1.34, and users are advised to update immediately.

    00021940
    7.3K followersView on X
  • Manage Multiple WordPress and Joomla Sites easily!@mysitesguru
    Patch

    Still running Smart Slider 3 on client sites? CVE-2026-3098 lets any subscriber download wp-config.php. Over 800K sites affected. Update to 3.5.1.34 and regenerate your salts. https://mysites.guru/blog/smart-slider-3-arbitrary-file-read-vulnerability/?utm_source=twitter&utm_medium=social #WordPress #Security https://t.co/LwwVOP7D3Z

    Post summary

    CVE‑2026‑3098 allows arbitrary file read from Smart Slider 3, affecting more than 800K WordPress sites; the advisory recommends updating to version 3.5.1.34 and regenerating salts to mitigate.

    0001178
    2.5K followersView on X
  • SOCRadar®@socradar
    Active Exploitation

    🚨 Dark Web Alert: New activity reveals high-stakes threats in Healthcare, ID data, and Web Apps. 🚫 TrakCare/InterSystems: Initial access for sale 🆔 Leaks: 4.8M U.S. Driver IDs + HK Healthcare data 🔓 Exploit: Smart Slider (CVE-2026-3098) being weaponized Read the full Intel: https://hubs.la/Q049HtH60 #CyberSecurity #DarkWeb #DataBreach #InfoSec

    Post summary

    The alert indicates that CVE‑2026‑3098 in the Smart Slider plugin is currently being weaponized on the dark web, with no provided PoC, exploit code, or patch details.

    00020286
    5.7K followersView on X
  • Manage Multiple WordPress and Joomla Sites easily!@mysitesguru
    Patch

    ICYMI: Smart Slider 3 has a vulnerability (CVE-2026-3098) that lets any subscriber download your wp-config.php. 800K sites affected. Update to 3.5.1.34 now. Then regenerate your salts. https://mysites.guru/blog/smart-slider-3-arbitrary-file-read-vulnerability/?utm_source=twitter&utm_medium=social #WordPress #Security https://t.co/6p4Qgydviz

    Post summary

    CVE-2026-3098 is an arbitrary file read vulnerability in Smart Slider 3 that permits subscribers to access wp-config.php; the recommended mitigation is to update to version 3.5.1.34 and regenerate salts.

    0001174
    2.5K followersView on X
  • Nullvy | CyberNews@NullvyNews
    General

    كشف خبراء الأمن السيبراني عن ثغرة أمنية خطيرة (CVE-2026-3098) في إضافة "Smart Slider 3" الشهيرة، والتي تستخدمها أكثر من 800 ألف منصة تعتمد على نظام ووردبريس، مما يضع بيانات نصف مليون موقع تحت تهديد مباشر بالاختراق الكامل. 📌 للتفاصيل الكاملة: 🔗 https://www.instagram.com/p/DWednesCEp0/?igsh=aDh0eTg2cHlrNmtx https://t.co/CtXcunuSmm

    Post summary

    The post publicly announces the discovery of CVE-2026-3098 in the Smart Slider 3 WordPress plugin, indicating a widespread potential security risk, yet it does not provide any proof of exploitation, patch information, or technical vulnerability details.

    0002080
    14 followersView on X
  • Mr.Rabbit@01ra66it
    Active Exploitation

    3/29 は、大規模な新規ゼロデイ公表日というより、Web公開面の取りやすい脆弱性、要人の個人メール侵害、継続中の国家系・公開羞恥型攻撃が前面に出た日でした。 特に、Smart Slider 3 の CVE-2026-3098 は、購読者レベル権限でも任意ファイル読取りが可能で、wp-config.php 経由のサイト乗っ取りに繋がり得ます。 加えて、Handala による FBI 長官 Kash Patel 氏の個人 Gmail 侵害は、政府データではなくても、個人アカウントを使った暴露・威圧が現実的な攻撃手段として機能していることを示しました。 根拠の中心は2点です。 1つ目は、BleepingComputer が CVE-2026-3098 について、Smart Slider 3 の actionExportAll に起因する任意ファイル読取りで、wp-config.php 取得から全面的なサイト侵害に発展し得ると報じている点です。 2つ目は、BleepingComputer と Reuters が Handala による Patel 氏個人メール侵害 と、FBI の「政府情報は含まれない」との説明を伝えている点です。 この日の実務優先順位は、 ① WordPress 資産の Smart Slider 3 バージョン確認 ② 会員権限ユーザーの異常行動確認 ③ 幹部・管理者の個人メール露出点検 ④ 個人アカウント起点の二次フィッシング監視 です。 3/29 は件数よりも、“低権限でも刺さるWeb弱点” と “個人アカウントを使った公開圧力” が印象的な日でした。

    Post summary

    The post emphasizes a real‑time attack on an FBI official’s personal Gmail by Handala and highlights the Smart Slider 3 CVE‑2026‑3098 flaw that permits arbitrary file reads and potential site takeover, stressing the risk of low‑privilege web vulnerabilities.

    00010454
    3.5K followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-3098 The Smart Slider 3 plugin for WordPress is vulnerable to Arbitrary File Read in all versions up to, and including, 3.5.1.33 via the 'actionExportAll' function. This mak… https://www.cve.org/CVERecord?id=CVE-2026-3098

    Post summary

    The statement discloses CVE-2026-3098, describing an arbitrary file read vulnerability in Smart Slider 3 through the 'actionExportAll' function, but does not mention any PoC, exploit, patch, or active exploitation.

    0001093
    56.9K followersView on X
  • Manage Multiple WordPress and Joomla Sites easily!@mysitesguru
    Patch

    Smart Slider 3 has a vulnerability (CVE-2026-3098) that lets any subscriber download your wp-config.php. 800K sites affected. Update to 3.5.1.34 now. Then regenerate your salts. https://mysites.guru/blog/smart-slider-3-arbitrary-file-read-vulnerability/?utm_source=twitter&utm_medium=social #WordPress #Security https://t.co/B0roYGWSig

    Post summary

    CVE‑2026‑3098 in Smart Slider 3 enables arbitrary file reads, affecting approximately 800k WordPress sites. The advisory recommends updating to release 3.5.1.34 and regenerating salts to mitigate the issue.

    0001062
    2.5K followersView on X
  • Ahmed Amin@AhmedAmin_CS
    Active Exploitation

    @TheHackersNews What makes this worse: this was the SECOND Smart Slider incident in two weeks. CVE-2026-3098 was patched in 3.5.1.34 days before. The update that fixed the vuln became the attack vector. "Update immediately" was literally the malware delivery.

    Post summary

    The tweet highlights that the patch update for CVE-2026-3098 itself was used as a malware delivery vector, indicating active exploitation in the wild.

    0000052
    37 followersView on X
  • Jamaica Cyber Incident Response Team (JaCIRT)@cirtgovjm
    General

    🚨 Security Advisory A critical vulnerability (CVE-2026-3098) has been identified in the Smart Slider 3 WordPress plugin Click here for more details:  https://cirt.gov.jm/advisory/smart-slider-3-wordpress-plugin-vulnerability-cve-2026-3098-exposes-sensitive-server-files #jacirt #nsoc #wordpress #vulnerability #cyber https://t.co/xVCVLi8B6q

    Post summary

    The tweet announces the discovery of CVE‑2026‑3098 in Smart Slider 3 but provides no further technical detail, exploitation information, or remediation guidance.

    0000093
    1.1K followersView on X
  • Brinztech@Brinztech_com
    General

    Brinztech Alert: CVE-2026-3098 Targets 800,000+ "Smart Slider 3" WordPress Sites https://www.brinztech.com/breach-alerts/brinztech-alert-cve-2026-3098-targets-800000-smart-slider-3-wordpress-sites/

    Post summary

    Brinztech announced an alert for CVE‑2026‑3098 that could affect more than 800,000 Smart Slider 3 WordPress sites, but the brief does not provide PoC, exploit details, patches, or evidence of active attacks.

    0000062
    58 followersView on X
  • セキュリティ対策Lab@securityLab_jp
    Disclosure

    WordPressのスライダー プラグイン Smart Slider 3に任意ファイル読み取り脆弱性(CVE-2026-3098)-80万超のWordPress サイトに影響 https://rocket-boys.co.jp/security-measures-lab/cve-2026-3098-wp-smart-slider-3-arbitrary-file-read/ #セキュリティ対策Lab #セキュリティ #Security #CybersecurityNews

    Post summary

    The post announces that WordPress Smart Slider 3 has an arbitrary file read flaw (CVE-2026-3098) affecting over 800,000 sites, but provides no PoC, exploit, patch, or active exploitation details.

    00000135
    363 followersView on X
  • s0rK@sorkxx
    Disclosure

    🚨 Más de 500.000 webs en riesgo Un fallo crítico en Smart Slider 3 permite acceder a credenciales sensibles en WordPress ⚠️ 👉 ¿Está tu web expuesta? https://www.s0rk.net/2026/03/cve-2026-3098-smart-slider-3-vulnerabilidad-wordpress-wp-config-robo-datos.html #WordPress #Ciberseguridad #Vulnerabilidad https://t.co/LdXJzSDcUk

    Post summary

    The tweet announces a critical Smart Slider 3 flaw in WordPress that could allow credential theft, but it does not provide PoC details, exploitation code, active attack evidence, or patch information.

    0000059
    76 followersView on X
  • Aviatrix Threat Research Center@aviatrixtrc
    Active Exploitation

    Attackers exploited CVE-2026-3098 in Smart Slider 3 to read wp-config.php files, escalating from subscriber to admin privileges across 500K WordPress sites. The campaign demonstrates how initial file disclosure vulnerabilities enable broader hosting environment compromise. Runtime segmentation helps contain lateral movement between hosted applications. #CloudSecurity 🔗 Full TRC analysis: https://aviatrix.ai/threat-research-center/smart-slider-3-plugin-vulnerability-2026

    Post summary

    The report documents widespread active exploitation of CVE‑2026‑3098 in Smart Slider 3, enabling attackers to read sensitive files and elevate privileges on roughly 500,000 WordPress sites.

    0000084
    1.9K followersView on X
  • EloViral@EloViral
    Patch

    🚨 Vulnerabilidade crítica no Smart Slider 3 afeta 800 mil sites WordPress Falha permite leitura de arquivos sensíveis por usuários com acesso mínimo. Patch disponível desde 24/03, mas 500 mil sites ainda vulneráveis. CVE-2026-3098 expõe riscos de plugins populares. Atualização imediata é essencial para segurança. #WordPress #Segurança https://www.bleepingcomputer.com/news/security/file-read-flaw-in-smart-slider-plugin-impacts-500k-wordpress-sites/

    Post summary

    The text announces a critical file‑read flaw in Smart Slider 3, highlights that a patch was released on March 24, yet many sites remain vulnerable, and urges immediate update.

    0000052
    9 followersView on X
  • Cybersecurity News Everyday@TweetThreatNews
    Patch

    A file read vulnerability in Smart Slider 3 (CVE-2026-3098) affects 500K+ WordPress sites, allowing subscriber-level users to access sensitive server files. Fixed in version 3.5.1.34. #WordPressRisk #PluginFlaw #USA https://ift.tt/hcGsrR0

    Post summary

    The tweet highlights a file‑read vulnerability in Smart Slider 3 affecting over 500,000 WordPress sites, notes that the issue is resolved in version 3.5.1.34, and underscores the availability of a patch.

    00000231
    3.9K followersView on X
  • Vivek | Cybersecurity@VivekIntel
    Disclosure

    Smart Slider 3 WordPress plugin flaw (CVE-2026-3098) lets low-privilege users read arbitrary files on 500K+ sites https://www.bleepingcomputer.com/news/security/file-read-flaw-in-smart-slider-plugin-impacts-500k-wordpress-sites/

    Post summary

    A newly disclosed CVE-2026-3098 flaw in the Smart Slider 3 WordPress plugin enables low‑privilege users to read arbitrary files on more than 500,000 sites.

    0000058
    817 followersView on X

Explore more