CVE-2026-12385: Nextendweb Smart Slider 3

Medium severity, CVSS 4.3. EPSS: 0.4% chance of exploitation in the next 30 days.

The Smart Slider 3 plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 3.5.1.37 via the 'keyword' parameter. This makes it possible for authenticated attackers, with contributor-level access and above, to extract titles and full content excerpts of private, draft, pending, trashed, and auto-draft posts authored by any user, including Administrators and Editors. The required nonce is emitted on /wp-admin/post-new.php, which is accessible to Contributor-level users via the edit_posts capability, meaning any Contributor can obtain the nonce needed to trigger the injection.

Affected products

  • Nextendweb Smart Slider 3: up to and including 3.5.1.37

Published 2026-07-13. Last modified 2026-07-14.