Smart Slider 3

This information is sourced from wpvulnerabilities.com. An open-source database of vulnerabilities maintained by the community. Help us out by submitting vulnerabilities!

Vulnerabilities

  • Input validation vulnerability in Smart Slider 3 3.5.1.28

    Fixed

    The Smart Slider 3 plugin for WordPress has a security issue that allows hackers to access sensitive information from the website's database. This is due to a lack of proper protection on a specific ...

    Read More
  • Access violation vulnerability in Smart Slider 3 3.5.1.22

    Fixed

    The Smart Slider 3 plugin for WordPress has a security issue that allows unauthorized changes to be made to data. This is because the upload function does not check for certain permissions. This vuln...

    Read More
  • Input validation vulnerability in Smart Slider 3 3.5.1.9

    Fixed

    The Smart Slider 3 plugin for WordPress has a security issue. It is vulnerable to something called Stored Cross-Site Scripting. This means that attackers

    Read More
  • Input validation vulnerability in Smart Slider 3 3.5.0.9

    Fixed

    The Smart Slider 3 Free and Pro WordPress plugins had an issue before version 3.5.0.9 which allowed attackers to store malicious code on the page. By default

    Read More
  • Output validation vulnerability in Smart Slider 3 3.5.1.9

    Fixed

    The Smart Slider 3 plugin for WordPress has a security issue with versions up to 3.5.1.9. This issue allows people with limited access to the website to inject a special type of code (PHP Object) whic...

    Read More
  • Input validation vulnerability in Smart Slider 3 3.5.1.13

    Fixed

    The Smart Slider 3 plugin for WordPress is not secure in versions up to 3.5.1.13. People with certain user permissions (such as Contributor) can put malicious web scripts in pages which will be execut...

    Read More
  • Output validation vulnerability in Smart Slider 3 3.5.1.9

    Fixed

    The Smart Slider 3 plugin for WordPress is not secure in versions up to and including 3.5.1.9. An attacker with administrator-level access can inject a special type of code (PHP Object) into the plugi...

    Read More