CYBERSECURITYTRACKER
TRACKING6,506 stories in this site build1,309 vulnerability news stories in this site build
Permanent story citation

Critical Supply Chain Compromise in Smart Slider 3 Pro: Full Malware Analysis

This page keeps the story as Cybersecurity Tracker first published it. If the tracker later corrects it, the correction appears below the original and never replaces it.

Back to newsStory 6285

As cited

Copy frozen at (site build).

threat intel

Critical Supply Chain Compromise in Smart Slider 3 Pro: Full Malware Analysis

An attacker compromised Nextend's update infrastructure and injected malware into Smart Slider 3 Pro version 3.5.1.35, distributing it through the official WordPress update channel for approximately 6 hours on April 7, 2026. The malware provides multiple backdoor entry points, including unauthenticated remote command execution via HTTP headers, an authenticated shell with PHP and OS command modes, hidden administrator accounts, and persistence across five separate locations including must-use plugins, theme files, and WordPress core directories. Sites running the compromised version should be treated as fully compromised and cleaned immediately; users should upgrade to version 3.5.1.36 or later.

Why it matters: WordPress site administrators using Smart Slider 3 Pro must immediately upgrade and audit for compromise, as any installation of version 3.5.1.35 grants attackers unauthenticated remote access and full server control through multiple persistent backdoors that survive plugin removal.

Source published
First seen by Cybersecurity Tracker

Source attribution

Correction

Correction recorded as of .

threat intel

Critical Supply Chain Compromise in Smart Slider 3 Pro: Full Malware Analysis

An attacker compromised Nextend's update infrastructure and injected malware into Smart Slider 3 Pro version 3.5.1.35, distributing it through the official WordPress update channel for approximately 6 hours on April 7, 2026. The malware provides multiple backdoor entry points, including unauthenticated remote command execution via HTTP headers, an authenticated shell with PHP and OS command modes, hidden administrator accounts, and persistence across five separate locations including must-use plugins, theme files, and WordPress core directories. Sites running the compromised version should be treated as fully compromised and cleaned immediately; users should upgrade to version 3.5.1.36 or later.

Why it matters: WordPress site administrators using Smart Slider 3 Pro must immediately upgrade and audit for compromise, as any installation of version 3.5.1.35 grants attackers unauthenticated remote access and full server control through multiple persistent backdoors that survive plugin removal.

VendorsGoogleWordPress
Source published
First seen by Cybersecurity Tracker

Source attribution

Glossary