Orizon[verified]@OrizonCyberDisclosure
The tweet announces CVE-2026-34424 as a critical vulnerability in Smart Slider 3 Pro, describes a remote-access toolkit injected into the plugin and urges users to apply a patch.
Giuseppe Paternicola[verified]@giuseppe_1337Active Exploitation
CVE-2026-34424 is a critical, unauthenticated RCE vulnerability in Smart Slider 3 Pro v3.5.1.35 that is actively exploited via the update system, resulting in backdoors and credential theft; WordPress and Joomla users are urged to remove the plugin immediately.
CTIWatch@ctiwatchcloudActive Exploitation
CVE‑2026‑34424 in Smart Slider 3 Pro is a high‑severity vulnerability (CVSS 9.8) that includes a multi‑stage remote access toolkit and is actively exploited in the wild.
CVE@CVEnewDisclosure
The post announces CVE‑2026‑34424 affecting Smart Slider 3 Pro, noting a multi‑stage remote access toolkit embedded via a compromised update system.
CVEFind.com@CveFindComPatch
The post announces a critical arbitrary code execution vulnerability in Smart Slider 3 Pro and urges users to update immediately as a mitigation.
0day Signal@0dayPublishingDisclosure
The post discloses a new supply‑chain poisoning vulnerability (CVE‑2026‑34424) affecting Smart Slider 3 Pro, detailing a pre‑authentication remote code execution vector through HTTP headers, but no PoC, exploit, or patch is referenced.