Nextend Smart Slider 3
cpe:2.3:a:nextendweb:smart_slider_3:*:*:*:*:wordpress:*:*
- <= 3.5.1.28
A time-based SQL injection vulnerability has been identified in the Smart Slider 3 plugin for WordPress, affecting all versions through 3.5.1.28. The issue arises from inadequate escaping of user-supplied data in the 'sliderid' parameter, coupled with insufficient preparation of the SQL query. This vulnerability allows authenticated attackers with Administrator-level access to inject additional SQL commands into existing queries, potentially leading to the extraction of sensitive information from the database.
Exploitation of this vulnerability allows for time-based SQL injection, where an attacker can manipulate SQL queries to extract sensitive data from the database.
Users are advised to update the Smart Slider 3 plugin to version 3.5.1.29 or a newer patched version.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.