Smart Slider 3 Pro version 3.5.1.35 for WordPress and Joomla contains a multi-stage remote access toolkit injected through a compromised update system that allows unauthenticated attackers to execute arbitrary code and commands. Attackers can trigger pre-authentication remote shell execution via HTTP headers, establish authenticated backdoors accepting arbitrary PHP code or OS commands, create hidden administrator accounts, exfiltrate credentials and access keys, and maintain persistence through multiple injection points including must-use plugins and core file modifications.
Metrics
Affected Vendors & Products
References
History
Tue, 14 Apr 2026 04:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Fri, 10 Apr 2026 09:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Wordpress
Wordpress wordpress |
|
| Vendors & Products |
Wordpress
Wordpress wordpress |
Thu, 09 Apr 2026 23:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Smart Slider 3 Pro version 3.5.1.35 for WordPress and Joomla contains a multi-stage remote access toolkit injected through a compromised update system that allows unauthenticated attackers to execute arbitrary code and commands. Attackers can trigger pre-authentication remote shell execution via HTTP headers, establish authenticated backdoors accepting arbitrary PHP code or OS commands, create hidden administrator accounts, exfiltrate credentials and access keys, and maintain persistence through multiple injection points including must-use plugins and core file modifications. | |
| Title | Smart Slider 3 Pro 3.5.1.35 Supply Chain Attack Remote Access Toolkit | |
| First Time appeared |
Nextendweb
Nextendweb smart Slider 3 |
|
| Weaknesses | CWE-506 | |
| CPEs | cpe:2.3:a:nextendweb:smart_slider_3:3.5.1.35:*:*:*:*:joomla:*:* cpe:2.3:a:nextendweb:smart_slider_3:3.5.1.35:*:*:*:*:wordpress:*:* |
|
| Vendors & Products |
Nextendweb
Nextendweb smart Slider 3 |
|
| References |
|
|
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: VulnCheck
Published: 2026-04-09T22:59:38.306Z
Updated: 2026-04-14T03:13:40.678Z
Reserved: 2026-03-27T15:24:06.752Z
Link: CVE-2026-34424
Updated: 2026-04-14T03:13:35.312Z
Status : Deferred
Published: 2026-04-09T23:17:00.540
Modified: 2026-04-15T15:00:32.790
Link: CVE-2026-34424
No data.