CVE · Medium

CVE-2022-45845 — Smart Slider 3 [smart-slider-3] < 3.5.1.11

CVE Vulnerability Type Severity Affected Fixed in Published Status
CVE-2022-45845 Smart Slider 3 [smart-slider-3] < 3.5.1.11 Deserialization of Untrusted Data Medium 4.3 < 3.5.1.11 3.5.1.11 2022-11-23

CVE-2022-45845

The Smart Slider 3 plugin through version 3.5.1.9 contains a PHP Object Injection vulnerability caused by unsafe deserialization of user-controlled data, which allows attackers with contributor-level access to inject malicious PHP objects. While the plugin itself lacks a gadget chain for exploitation, the presence of one in other installed plugins or themes could potentially enable an attacker to execute arbitrary code, access sensitive information, or delete files on the affected system.

Based on public CVE data (MITRE/NVD).

Scan your WordPress site free

No signup, no credit card — enter your URL and get a security report in seconds.