Security
Malicious Smart Slider 3 Pro release affected Joomla sites
Nextend’s Smart Slider 3 Pro 3.5.1.35 was a malicious release distributed through the official update channel, giving affected Joomla sites a remote code-execution backdoor.
mySites.guru published research describing the incident as a supply-chain compromise of Nextend’s update infrastructure, rather than a conventional extension vulnerability. The affected release could execute shell commands or PHP code and was also associated with hidden administrator accounts and persistence files.
The incident affects the Joomla and WordPress editions of Smart Slider 3 Pro. The reported version status is:
3.5.1.35: malicious and compromised3.5.1.34and earlier: not affected by this incident3.5.1.36: clean replacement
The supplied report gives no formal severity rating or separate CVE for the supply-chain compromise. It references CVE-2026-3098 as an earlier arbitrary file-read issue in Smart Slider 3, not as the identifier for this malicious release.
Administrators who installed 3.5.1.35 should update to 3.5.1.36, then treat the site as potentially compromised. Check for unauthorized users, suspicious cf_check.php files and known backdoor strings, and use Nextend’s official cleanup script. Updating alone does not remove changes made before the upgrade.
Originally reported by mySites.guru.