CVE · High

CVE-2022-3357 — Smart Slider 3 [smart-slider-3] < 3.5.1.11

CVE Vulnerability Type Severity Affected Fixed in Published Status
CVE-2022-3357 Smart Slider 3 [smart-slider-3] < 3.5.1.11 Deserialization of Untrusted Data High 8.8 < 3.5.1.11 3.5.1.11 2022-10-10

CVE-2022-3357

The Smart Slider 3 plugin through version 3.5.1.9 contains a PHP Object Injection vulnerability that occurs during file import operations due to unsafe deserialization of untrusted data. Attackers with administrator privileges can exploit this to inject malicious PHP objects, and while the plugin itself lacks a gadget chain for exploitation, the presence of such chains in other installed plugins or themes could enable attackers to perform arbitrary file deletion, access confidential information, or achieve remote code execution.

Based on public CVE data (MITRE/NVD).

Scan your WordPress site free

No signup, no credit card — enter your URL and get a security report in seconds.