WordPress · Smart Slider 3 · CVE-2026-12385
**Name of the Vulnerable Software and Affected Versions**
Smart Slider 3 versions prior to 3.5.1.38
**Description**
Authenticated attackers with contributor-level access and above can cause sensitive information exposure. By manipulating the `keyword` parameter, an attacker can extract titles and full content excerpts of private, draft, pending, trashed, and auto-draft posts authored by any user, including Administrators and Editors. The necessary nonce is available on the '/wp-admin/post-new.php' endpoint, which is accessible to users with the `edit posts` capability.
**Recommendations**
Update the plugin to a version newer than 3.5.1.37.
Avoid using the `keyword` parameter in the affected plugin until the update is applied.