Unauthorized Data Access in Smart Slider 3 Plugin for WordPress
CVE-2026-4065
5.4MEDIUM
What is CVE-2026-4065?
The Smart Slider 3 plugin for WordPress lacks proper capability checks, allowing attackers with Contributor-level access or higher to gain unauthorized access to data. Multiple wp_ajax_smart-slider3 controller actions fail to enforce necessary permissions, enabling these attackers to enumerate slider metadata and manipulate image storage records. This is particularly concerning as the display_admin_ajax() method does not properly authenticate actions against users' capabilities, exposing sensitive functionalities to potential exploitation.
Affected Version(s)
Smart Slider 3 0 <= 3.5.1.33