Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Tue, 14 Apr 2026 04:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Fri, 10 Apr 2026 09:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Wordpress
Wordpress wordpress |
|
| Vendors & Products |
Wordpress
Wordpress wordpress |
Thu, 09 Apr 2026 23:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Smart Slider 3 Pro version 3.5.1.35 for WordPress and Joomla contains a multi-stage remote access toolkit injected through a compromised update system that allows unauthenticated attackers to execute arbitrary code and commands. Attackers can trigger pre-authentication remote shell execution via HTTP headers, establish authenticated backdoors accepting arbitrary PHP code or OS commands, create hidden administrator accounts, exfiltrate credentials and access keys, and maintain persistence through multiple injection points including must-use plugins and core file modifications. | |
| Title | Smart Slider 3 Pro 3.5.1.35 Supply Chain Attack Remote Access Toolkit | |
| First Time appeared |
Nextendweb
Nextendweb smart Slider 3 |
|
| Weaknesses | CWE-506 | |
| CPEs | cpe:2.3:a:nextendweb:smart_slider_3:3.5.1.35:*:*:*:*:joomla:*:* cpe:2.3:a:nextendweb:smart_slider_3:3.5.1.35:*:*:*:*:wordpress:*:* |
|
| Vendors & Products |
Nextendweb
Nextendweb smart Slider 3 |
|
| References |
|
|
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: VulnCheck
Published:
Updated: 2026-05-14T16:05:59.351Z
Reserved: 2026-03-27T15:24:06.752Z
Link: CVE-2026-34424
Updated: 2026-04-14T03:13:35.312Z
Status : Deferred
Published: 2026-04-09T23:17:00.540
Modified: 2026-04-15T15:00:32.790
Link: CVE-2026-34424
No data.
OpenCVE Enrichment
Updated: 2026-04-10T09:27:31Z