Impact
The Smart Slider 3 plugin for WordPress contains a stored cross‑site scripting flaw in the "slider" block attribute. An authenticated user with contributor level or higher can embed arbitrary JavaScript that is saved to the post. When an editor or administrator opens the affected post in the WordPress block editor, the injected script executes in their browser. This can lead to session hijacking, credential theft, defacement or broader compromise of the site’s administrative interface.
Affected Systems
All installations of the Smart Slider 3 plugin for WordPress, specifically versions up to and including 3.5.1.38 delivered by NextendWeb. Any WordPress site running this plugin is susceptible unless the version is upgraded or the plugin is removed.
Risk and Exploitability
The CVSS score of 6.4 indicates a moderate severity vulnerability. The EPSS score is not available, and the issue has not been catalogued in the CISA KEV list. Exploitation requires authenticated access with contributor permissions, making the threat limited to users with such privileges. An attacker exploiting the flaw would need to create or edit a slide block containing malicious code, which then executes only when a privileged user opens the post in the editor. The lack of a public exploitation report suggests the vulnerability is not yet actively weaponised, but its moderate score and the ease of abuse for privileged users warrant prompt attention.
OpenCVE Enrichment