CVE-2026-34424Disclosure

HIGHCVSS 9.3 · CRITICAL

Exploitation observed; activity peaked at 4 mentions and remains active

Immediate actions

  • Patch affected systems immediately
  • Assume compromise if assets are exposed
  • Hunt for exploitation attempts and persistence artifacts

Recommended action window: Immediate (within 24h)

NVD description

Smart Slider 3 Pro version 3.5.1.35 for WordPress and Joomla contains a multi-stage remote access toolkit injected through a compromised update system that allows unauthenticated attackers to execute arbitrary code and commands. Attackers can trigger pre-authentication remote shell execution via HTTP headers, establish authenticated backdoors accepting arbitrary PHP code or OS commands, create hidden administrator accounts, exfiltrate credentials and access keys, and maintain persistence through multiple injection points including must-use plugins and core file modifications.

6.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-506

Priority

HIGH

Exploitation

ACTIVE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Threat summary

  • Active exploitation appears in 2 classified signals
  • Exploit tooling references are present in monitored signal
  • Patch or workaround signal is available
  • 6 mentions across 3 observed days

What's happening

  • Active exploitation reported across 2 signals
  • Exploit tool or code specified in 1 signal
  • Patch or workaround mentioned in 2 signals
  • Technical details provided in 6 signals
  • Disclosure: 3 classified signals
  • Peaked 2d ago at 4 mentions (2026-04-09); latest day: 1
  • 6 total mentions across 3 days

Deep dive

Activity timeline6 mentions / 3d
01234Mentions · 2026-04-09: 4Mentions · 2026-04-10: 1Mentions · 2026-04-13: 1Exploit Tool / Code · 2026-04-10: 1Active Exploitation · 2026-04-09: 1Active Exploitation · 2026-04-13: 1Patch / Workaround · 2026-04-09: 1Patch / Workaround · 2026-04-10: 1Technical Details · 2026-04-09: 4Technical Details · 2026-04-10: 1Technical Details · 2026-04-13: 104-0904-1004-13
Signal classification3 categories
Disclosure
350.0%
Active Exploitation
233.3%
Patch
116.7%
Referenced assets4 URLs
Classification over time
DateTotalLabels
2026-04-094
Active Exploitation1Disclosure2Patch1
2026-04-101
Disclosure1
2026-04-131
Active Exploitation1
Full discourse6 posts
  • Orizon@OrizonCyber
    Disclosure

    🚨 CVE-2026-34424 — CVSS 9.8/10 ██████████ Smart Slider 3 Pro version 3.5.1.35 for WordPress and Joomla contains a multi-stage remote access toolkit injected... Severity: CRITICAL Patch now. #cybersecurity #CVE https://t.co/qaLF59vfk5

    Post summary

    The tweet announces CVE-2026-34424 as a critical vulnerability in Smart Slider 3 Pro, describes a remote-access toolkit injected into the plugin and urges users to apply a patch.

    1000160
    16 followersView on X
  • CTIWatch@ctiwatchcloud
    Active Exploitation

    ⚠️ CISA KEV — CVE-2026-34424 Smart Slider 3 Pro version 3.5.1.35 for WordPress and Joomla contains a multi-stage remote access toolkit injected throu... CVSS 9.8 · Actively exploited in the wild 🔗 http://ctiwatch.cloud/vulnerabilities/CVE-2026-34424 #CISA #KEV #Vulnerability #CyberSecurity

    Post summary

    CVE‑2026‑34424 in Smart Slider 3 Pro is a high‑severity vulnerability (CVSS 9.8) that includes a multi‑stage remote access toolkit and is actively exploited in the wild.

    0001088
    5.6K followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-34424 Smart Slider 3 Pro version 3.5.1.35 for WordPress and Joomla contains a multi-stage remote access toolkit injected through a compromised update system that allows una… https://www.cve.org/CVERecord?id=CVE-2026-34424

    Post summary

    The post announces CVE‑2026‑34424 affecting Smart Slider 3 Pro, noting a multi‑stage remote access toolkit embedded via a compromised update system.

    00000177
    57.0K followersView on X
  • CVEFind.com@CveFindCom
    Patch

    [CVE-2026-34424: CRITICAL] Critical vulnerability in Smart Slider 3 Pro 3.5.1.35 for WordPress and Joomla allows attackers to execute arbitrary code. Update immediately to protect against remote access threats.#cve,CVE-2026-34424,#cybersecurity https://cvefind.com/CVE-2026-34424

    Post summary

    The post announces a critical arbitrary code execution vulnerability in Smart Slider 3 Pro and urges users to update immediately as a mitigation.

    0000079
    619 followersView on X
  • Giuseppe Paternicola@giuseppe_1337
    Active Exploitation

    🚨 CRITICAL: CVE-2026-34424 (CVSS 9.8) Smart Slider 3 Pro v3.5.1.35 compromised via update system. Unauthenticated RCE, backdoors, credential theft. WordPress & Joomla users: Remove immediately. #CVE #Vulnerability #PatchNow #ThreatIntel https://t.co/r2c2lxNZXn

    Post summary

    CVE-2026-34424 is a critical, unauthenticated RCE vulnerability in Smart Slider 3 Pro v3.5.1.35 that is actively exploited via the update system, resulting in backdoors and credential theft; WordPress and Joomla users are urged to remove the plugin immediately.

    0000070
    10 followersView on X
  • 0day Signal@0dayPublishing
    Disclosure

    🚨 CVE-2026-34424: Smart Slider 3 Pro 3.5.1.35 Supp... Supply chain poisoning with pre-auth RCE via HTTP headers—this isn't just a plugin compromise, it's a masterclass in pe... https://zerodaysignal.com/vulnerability/CVE-2026-34424 #netsec #vulnerability #CVE #sysadmin #zeroday

    Post summary

    The post discloses a new supply‑chain poisoning vulnerability (CVE‑2026‑34424) affecting Smart Slider 3 Pro, detailing a pre‑authentication remote code execution vector through HTTP headers, but no PoC, exploit, or patch is referenced.

    0000083
    204 followersView on X

Explore more