CVE · Medium

CVE-2026-12385 — Smart Slider 3 [smart-slider-3] < 3.5.1.38

CVE Vulnerability Type Severity Affected Fixed in Published Status
CVE-2026-12385 Smart Slider 3 [smart-slider-3] < 3.5.1.38 Exposure of Sensitive Information to an Unauthorized Actor Medium 4.3 < 3.5.1.38 3.5.1.38 2026-07-13

CVE-2026-12385

The Smart Slider 3 plugin for WordPress contains a flaw in versions up to 3.5.1.37 that allows attackers with contributor access or higher to view sensitive information about posts authored by other users. This is due to the exposure of titles and content excerpts through the 'keyword' parameter, which can be accessed using a nonce emitted on the /wp-admin/post-new.php page. As contributors have permission to edit posts, they can obtain this nonce and exploit the vulnerability.

Based on public CVE data (MITRE/NVD).

Scan your WordPress site free

No signup, no credit card — enter your URL and get a security report in seconds.