CVE Database /
CVE-2026-12385
CVE · Medium
CVE-2026-12385 — Smart Slider 3 [smart-slider-3] < 3.5.1.38
| CVE |
Vulnerability |
Type |
Severity |
Affected |
Fixed in |
Published |
Status |
|
CVE-2026-12385
|
Smart Slider 3 [smart-slider-3] < 3.5.1.38 |
Exposure of Sensitive Information to an Unauthorized Actor |
Medium
4.3
|
< 3.5.1.38
|
3.5.1.38 |
2026-07-13 |
—
|
CVE-2026-12385
The Smart Slider 3 plugin for WordPress contains a flaw in versions up to 3.5.1.37 that allows attackers with contributor access or higher to view sensitive information about posts authored by other users. This is due to the exposure of titles and content excerpts through the 'keyword' parameter, which can be accessed using a nonce emitted on the /wp-admin/post-new.php page. As contributors have permission to edit posts, they can obtain this nonce and exploit the vulnerability.
Based on public CVE data (MITRE/NVD).
Scan your WordPress site free
No signup, no credit card — enter your URL and get a security report in seconds.
See the full security page for this plugin
Browse the CVE database
Browse all security findings