PLUGIN SECURITY

Is Smart Slider 3 safe?

Responsive slider plugin to create sliders in visual editor easily. Build beautiful image slider, layer slider, video slider, post slider, and more.

What this plugin does

  • Slug: smart-slider-3
  • Author: Nextendweb
  • 800000+ active installs
  • 98/100 rating (1123 reviews on wordpress.org)
  • 24435929 all-time downloads
  • On WordPress.org since 2015-11-12

carousel slidergalleryimage slidersliderslideshow

Maintenance status

  • Latest known version: 3.5.1.38
  • Last updated: 2026-08-19 11:47am GMT
  • Tested up to WordPress: 7.0.4
  • Requires PHP: 7.0+
  • Max supported PHP (analyzed): <8.0

Known vulnerabilities

12 known CVEs on file for Smart Slider 3.

CVE Vulnerability Type Severity Affected Fixed in Published Status
CVE-2026-12385 Smart Slider 3 [smart-slider-3] < 3.5.1.38 Exposure of Sensitive Information to an Unauthorized Actor Medium 4.3 < 3.5.1.38 3.5.1.38 2026-07-13 ✓ fixed in latest
CVE-2026-15798 Smart Slider 3 [smart-slider-3] < 3.5.1.39 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Medium 6.4 < 3.5.1.39 3.5.1.39 2026-07-13 ⚠ update needed
CVE-2026-9197 Smart Slider 3 [smart-slider-3] < 3.5.1.37 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') Medium 4.9 < 3.5.1.37 3.5.1.37 2026-06-05 ✓ fixed in latest
CVE-2024-3027 Smart Slider 3 [smart-slider-3] < 3.5.1.23 Improper Authorization Medium 6.4 < 3.5.1.23 3.5.1.23 2024-04-12 ✓ fixed in latest
CVE-2023-0660 Smart Slider 3 [smart-slider-3] < 3.5.1.14 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Medium 5.4 < 3.5.1.14 3.5.1.14 2023-02-28 ✓ fixed in latest
CVE-2022-45845 Smart Slider 3 [smart-slider-3] < 3.5.1.11 Deserialization of Untrusted Data Medium 4.3 < 3.5.1.11 3.5.1.11 2022-11-23 ✓ fixed in latest
CVE-2022-45843 Smart Slider 3 [smart-slider-3] < 3.5.1.11 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Medium 5.4 < 3.5.1.11 3.5.1.11 2022-11-23 ✓ fixed in latest
CVE-2022-3357 Smart Slider 3 [smart-slider-3] < 3.5.1.11 Deserialization of Untrusted Data High 8.8 < 3.5.1.11 3.5.1.11 2022-10-10 ✓ fixed in latest
+ 7 more known vulnerabilities
CVE Vulnerability Type Severity Affected Fixed in Published Status
CVE-2021-24382 Smart Slider 3 [smart-slider-3] < 3.5.0.9 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Medium 5.4 < 3.5.0.9 3.5.0.9 2021-06-07 ✓ fixed in latest
Smart Slider 3 [smart-slider-3] < 3.5.1.29 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') Medium 4.9 < 3.5.1.29 3.5.1.29 0000-00-00 ✓ fixed in latest
Smart Slider 3 [smart-slider-3] < 3.5.1.34 Unknown < 3.5.1.34 3.5.1.34 0000-00-00 ✓ fixed in latest
Smart Slider 3 [smart-slider-3] < 3.5.1.34 Medium 5.4 < 3.5.1.34 3.5.1.34 0000-00-00 ✓ fixed in latest
CVE-2025-6348 Smart Slider 3 < 3.5.1.29 - Admin+ SQL Injection Unknown < 3.5.1.29 3.5.1.29 ✓ fixed in latest
CVE-2026-3098 Smart Slider 3 < 3.5.1.34 - Subscriber+ Arbitrary File Read via actionExportAll Unknown < 3.5.1.34 3.5.1.34 ✓ fixed in latest
CVE-2026-4065 Smart Slider 3 < 3.5.1.34 - Contributor+ Slider Data Read and Image Record Manipulation Unknown < 3.5.1.34 3.5.1.34 ✓ fixed in latest

How to fix it

Keep Smart Slider 3 updated — 3.5.1.38 is the latest version on wordpress.org, and each CVE above lists the exact release that fixed it ("Fixed in").

This is the plugin's full known vulnerability history, not a scan of any specific installation — run a free scan of your own site to check your exact installed version.

Safer / more established alternatives

Check your own WordPress site

Run a free passive scan now, or create a free account and install the WP Clinic plugin for a deep scan of your whole hosting account and AI-assisted repair.