Medium 5.4
2026-04-08< 3.5.1.34
Smart Slider 3 <= 3.5.1.33 - Missing Authorization to Authenticated (Contributor+) Slider Data Read and Image Record Manipulation
Minimum safe version
3.5.1.34
Update to 3.5.1.34 or later to address 9 fixable vulnerabilities
Smart Slider 3 <= 3.5.1.33 - Missing Authorization to Authenticated (Contributor+) Slider Data Read and Image Record Manipulation
Smart Slider 3 <= 3.5.1.33 - Authenticated (Subscriber+) Arbitrary File Read via actionExportAll
Smart Slider 3 <= 3.5.1.28 - Authenticated (Administrator+) SQL Injection via `sliderid` Parameter
WordPress Smart Slider 3 Plugin <= 3.5.1.22 is vulnerable to Broken Access Control
CVE-2023-0660
CVE-2022-45843
CVE-2022-45845
CVE-2022-3357
CVE-2021-24382