Unauthorized Data Access in Smart Slider 3 Plugin for WordPress
CVE-2026-4065

5.4MEDIUM

Key Information:

Vendor

WordPress

Vendor
CVE Published:
7 April 2026

What is CVE-2026-4065?

The Smart Slider 3 plugin for WordPress lacks proper capability checks, allowing attackers with Contributor-level access or higher to gain unauthorized access to data. Multiple wp_ajax_smart-slider3 controller actions fail to enforce necessary permissions, enabling these attackers to enumerate slider metadata and manipulate image storage records. This is particularly concerning as the display_admin_ajax() method does not properly authenticate actions against users' capabilities, exposing sensitive functionalities to potential exploitation.

Affected Version(s)

Smart Slider 3 0 <= 3.5.1.33

References

CVSS V3.1

Score:
5.4
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

darkestmode
.