Skip to main content

Threat intelligence

Smart Slider 3 <= 3.5.1.37 - Missing Authorization to Authenticated (Contributor+) Sensitive Information Exposure via WP_Query Parameter Injection via 'keyword' Parameter

CVE-2026-12385 · smart-slider-3

Important: Seeing this vulnerability listed does not mean your website is affected. Exposure depends on whether you run Smart Slider 3 at a vulnerable version. How SiteRespond intelligence works

Vulnerability
Smart Slider 3 <= 3.5.1.37 - Missing Authorization to Authenticated (Contributor+) Sensitive Information Exposure via WP_Query Parameter Injection via 'keyword' Parameter
Affected software
smart-slider-3(Plugin)
Affected versions
  • ≤ 3.5.1.37
Authentication
Authenticated (see advisory title)
Vulnerability type
Other
Published
13 July 2026
CISA KEV
Not listed in CISA KEV at last catalog refresh
Impact
This advisory describes a other issue in the affected software. Review the source advisory and your installed version to assess exposure.
Source

Data imported from Wordfence Intelligence (advisory a782d975-74ce-4265-9312-435b3585a5c6). Methodology and redistribution notes

Check whether your installed version is affected

SiteRespond Defence matches your installed Smart Slider 3 version against this catalog when the Defence plugin is connected to your WordPress site.