The Exploit

Security Recommendations

Smart Slider 3 Pro WordPress/Joomla Plugin Supply Chain Compromise

Smart Slider 3 Pro WordPress/Joomla Plugin Supply Chain Compromise

There has been one constant recommendation that has spanned my years as a System Administrator, through my role as a Senior Information Security Analyst, and even now into my role as a Lead Penetration Tester here at Raxis: stay up to date on patches. Update often to stay ahead of malicious actors that may not have reached your environment yet.

Lately, however, that mantra has resulted in organizations inadvertently compromising their own systems through supply chain attacks. Most recently, at least at the time of writing this, is the WordPress and Joomla plugin Smart Slider 3 Pro that briefly served a malicious version of the plugin to any website that saw a new version was available and wanted to stay on top of security by patching often.

Steps to Take Now

The affected version, 3.5.1.35, was served from Nextend’s update servers on April 7th, 2026, for a couple of hours. If you or your organization is responsible for a WordPress or Joomla site, audit your plugins immediately and, if you find Smart Slider 3 Pro version 3.5.1.35, consider your website compromised and follow the steps in the security advisory.

Note that this only affected the Pro version of the plugin. The Pro version is uniquely served from Nextend’s own update servers and avoids using WordPress and Joomla’s extension registries that the free/non-Pro version of Smart Slider 3 uses.

Reputational Damage

While a WordPress site may be just a marketing tool, it is also the client-facing side of your organization. If your website ends up on a blacklist, it affects both prospective and current customers. Not only does it potentially prevent them from accessing your site until you work to clean up the compromise, but it also does reputational damage in the minds of your clients. 

If you want to keep a constant eye on the vulnerabilities within your WordPress sites, or any external facing infrastructure, consider reaching out to Raxis to learn more about our Raxis Attack Penetration Testing as a Service (PTaaS) options for continual monitoring and unlimited penetration testing.

Keep Reading

Cool Tools Series: Reptyr

Jason Taylor brings highlights reptyr in our Cool Tools series, showing how to take a long-running process, like an Nmap scan, and move it to a new screen.

Request a quote

Tell Us What You Need Tested

We usually respond in one business day.

Please let us know what's on your mind. Include any details about your target environment, timeline, or compliance drivers.