Back to overview

CVE-2026-34424

CRITICAL
9.8
CVSS 3.1
Description
Smart Slider 3 Pro version 3.5.1.35 for WordPress and Joomla contains a multi-stage remote access toolkit injected through a compromised update system that allows unauthenticated attackers to execute arbitrary code and commands. Attackers can trigger pre-authentication remote shell execution via HTTP headers, establish authenticated backdoors accepting arbitrary PHP code or OS commands, create hidden administrator accounts, exfiltrate credentials and access keys, and maintain persistence through multiple injection points including must-use plugins and core file modifications.

Metadata

CVE ID
CVE-2026-34424
State
PUBLISHED
Assigner
VulnCheck
Reserved
2026-03-27 15:24 UTC
Published
2026-04-09 22:59 UTC
Last updated
2026-05-14 16:05 UTC
Primary CWE
CWE-506
Embedded Malicious Code
Vendor / Product
Nextendweb / Smart Slider 3 Pro for WordPress
Sources
cve.org  ·  NVD

Severity & Metrics

9.8 CRITICAL CVSS 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
SSVC — CISA Coordinator
Exploitation
none
Automatable
yes
Tech. Impact
total
Affected products (2)
VendorProductPlatformVersions
Nextendweb Smart Slider 3 Pro for Joomla 3.5.1.35, 0 ≤ 3.5.1.34, 3.5.1.36
Nextendweb Smart Slider 3 Pro for WordPress 3.5.1.35, 0 ≤ 3.5.1.34, 3.5.1.36
Weakness (CWE)
CWESourceDescription
CWE-506 cna Embedded Malicious Code
CVSS scores (2)
ScoreSeverityVersionSourceVector
9.8 CRITICAL 3.1 cna CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
9.3 CRITICAL 4.0 cna CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
Back to overview