Smart Slider 3 Pro version 3.5.1.35 for WordPress and Joomla contains a multi-stage remote access toolkit injected through a compromised update system that allows unauthenticated attackers to execute arbitrary code and commands. Attackers can trigger pre-authentication remote shell execution via HTTP headers, establish authenticated backdoors accepting arbitrary PHP code or OS commands, create hidden administrator accounts, exfiltrate credentials and access keys, and maintain persistence through multiple injection points including must-use plugins and core file modifications.
Metrics
Affected Vendors & Products
References
History
Thu, 09 Apr 2026 23:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Smart Slider 3 Pro version 3.5.1.35 for WordPress and Joomla contains a multi-stage remote access toolkit injected through a compromised update system that allows unauthenticated attackers to execute arbitrary code and commands. Attackers can trigger pre-authentication remote shell execution via HTTP headers, establish authenticated backdoors accepting arbitrary PHP code or OS commands, create hidden administrator accounts, exfiltrate credentials and access keys, and maintain persistence through multiple injection points including must-use plugins and core file modifications. | |
| Title | Smart Slider 3 Pro 3.5.1.35 Supply Chain Attack Remote Access Toolkit | |
| First Time appeared |
Nextendweb
Nextendweb smart Slider 3 |
|
| Weaknesses | CWE-506 | |
| CPEs | cpe:2.3:a:nextendweb:smart_slider_3:3.5.1.35:*:*:*:*:joomla:*:* cpe:2.3:a:nextendweb:smart_slider_3:3.5.1.35:*:*:*:*:wordpress:*:* |
|
| Vendors & Products |
Nextendweb
Nextendweb smart Slider 3 |
|
| References |
|
|
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: VulnCheck
Published:
Updated: 2026-04-09T22:59:38.306Z
Reserved: 2026-03-27T15:24:06.752Z
Link: CVE-2026-34424
No data.
Status : Received
Published: 2026-04-09T23:17:00.540
Modified: 2026-04-09T23:17:00.540
Link: CVE-2026-34424
No data.
OpenCVE Enrichment
No data.