Smart Slider 3 SQL Injection Vulnerability in WordPress

Vulnerability

A time-based SQL injection vulnerability has been identified in the Smart Slider 3 plugin for WordPress, affecting all versions through 3.5.1.28. The issue arises from inadequate escaping of user-supplied data in the 'sliderid' parameter, coupled with insufficient preparation of the SQL query. This vulnerability allows authenticated attackers with Administrator-level access to inject additional SQL commands into existing queries, potentially leading to the extraction of sensitive information from the database.

Impact

Exploitation of this vulnerability allows for time-based SQL injection, where an attacker can manipulate SQL queries to extract sensitive data from the database.

Remediation

Users are advised to update the Smart Slider 3 plugin to version 3.5.1.29 or a newer patched version.

Added: Jul 30, 2025, 9:16 AM
Updated: Jul 30, 2025, 9:16 AM

Vulnerability Rating

Custom Algorithm
spread
6.4
impact
2.5
exploitability
5.6
remediation
7.7
relevance
0.3
threat
3.2
urgency
2.9
incentive
1.7

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.