CVE-2022-45845
The Smart Slider 3 plugin through version 3.5.1.9 contains a PHP Object Injection vulnerability caused by unsafe deserialization of user-controlled data, which allows attackers with contributor-level access to inject malicious PHP objects. While the plugin itself lacks a gadget chain for exploitation, the presence of one in other installed plugins or themes could potentially enable an attacker to execute arbitrary code, access sensitive information, or delete files on the affected system.
Based on public CVE data (MITRE/NVD).