As cited
Copy frozen at (site build).
threat intel
Critical Supply Chain Compromise in Smart Slider 3 Pro: Full Malware Analysis
An attacker compromised Nextend's update infrastructure and injected malware into Smart Slider 3 Pro version 3.5.1.35, distributing it through the official WordPress update channel for approximately 6 hours on April 7, 2026. The malware provides multiple backdoor entry points, including unauthenticated remote command execution via HTTP headers, an authenticated shell with PHP and OS command modes, hidden administrator accounts, and persistence across five separate locations including must-use plugins, theme files, and WordPress core directories. Sites running the compromised version should be treated as fully compromised and cleaned immediately; users should upgrade to version 3.5.1.36 or later.
Why it matters: WordPress site administrators using Smart Slider 3 Pro must immediately upgrade and audit for compromise, as any installation of version 3.5.1.35 grants attackers unauthenticated remote access and full server control through multiple persistent backdoors that survive plugin removal.
- Source published
- First seen by Cybersecurity Tracker
Source attribution
Correction
Correction recorded as of .
threat intel
Critical Supply Chain Compromise in Smart Slider 3 Pro: Full Malware Analysis
An attacker compromised Nextend's update infrastructure and injected malware into Smart Slider 3 Pro version 3.5.1.35, distributing it through the official WordPress update channel for approximately 6 hours on April 7, 2026. The malware provides multiple backdoor entry points, including unauthenticated remote command execution via HTTP headers, an authenticated shell with PHP and OS command modes, hidden administrator accounts, and persistence across five separate locations including must-use plugins, theme files, and WordPress core directories. Sites running the compromised version should be treated as fully compromised and cleaned immediately; users should upgrade to version 3.5.1.36 or later.
Why it matters: WordPress site administrators using Smart Slider 3 Pro must immediately upgrade and audit for compromise, as any installation of version 3.5.1.35 grants attackers unauthenticated remote access and full server control through multiple persistent backdoors that survive plugin removal.
- Source published
- First seen by Cybersecurity Tracker