Nextendweb develops WordPress plugins focused on social login and slider functionality, a niche but prominent segment of the WordPress ecosystem. The vendor's disclosures concentrate in products such as Smart Slider 3 and its Facebook Connect and Twitter Connect integrations, where the recurring exposure centers on cross-site scripting and untrusted deserialization—classic input-handling and code-execution risks in plugin architecture. Public exploit code has frequently become available for Nextendweb vulnerabilities, making timely patching critical for WordPress administrators running these integrations. Current exploitation activity, severity breakdown, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Nextendweb over time
Signals from CVEs in this vendor scope (16 CVEs).
16 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2022-3357HIGH The Smart Slider 3 WordPress plugin before 3.5.1.11 unserialises the content of an imported file, which could lead to PHP object injection issues when a user import (intentionally | Oct 31, 2022 | 8.8 | 28 | NO | NO |
CVE-2026-3098MEDIUM The Smart Slider 3 plugin for WordPress is vulnerable to Arbitrary File Read in all versions up to, and including, 3.5.1.33 via the 'actionExportAll' function. This makes it possib | Mar 27, 2026 | 6.5 | 27 | NO | NO |
CVE-2026-9197MEDIUM The Smart Slider 3 plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 3.5.1.36 via the replaceHTMLImage function. This makes it possibl | Jun 6, 2026 | 4.9 | 26 | NO | NO |
CVE-2026-12385MEDIUM The Smart Slider 3 plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 3.5.1.37 via the 'keyword' parameter. This makes it po | Jul 13, 2026 | 4.3 | 25 | NO | NO |
CVE-2025-58031MEDIUM Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Nextendweb Nextend Facebook Connect nextend-facebook-connect allows Stored XS | Sep 22, 2025 | 6.5 | 22 | NO | NO |
CVE-2022-45845HIGH Deserialization of Untrusted Data vulnerability in Nextend Smart Slider 3.This issue affects Smart Slider 3: from n/a through 3.5.1.9. | Jan 19, 2024 | 8.8 | 22 | NO | NO |
CVE-2014-8800MEDIUM Cross-site scripting (XSS) vulnerability in nextend-facebook-settings.php in the Nextend Facebook Connect plugin before 1.5.1 for WordPress allows remote attackers to inject arbitr | Dec 5, 2014 | 4.3 | 22 | NO | YES |
CVE-2026-4065MEDIUM The Smart Slider 3 plugin for WordPress is vulnerable to unauthorized access and modification of data due to missing capability checks on multiple wp_ajax_smart-slider3 controller | Apr 7, 2026 | 5.4 | 21 | NO | NO |
CVE-2022-45843MEDIUM Auth. (contributor+) Stored Cross-Site Scripting vulnerability in Nextend Smart Slider 3 plugin <= 3.5.1.9 versions. | Mar 23, 2023 | 5.4 | 20 | NO | NO |
CVE-2025-6348MEDIUM The Smart Slider 3 plugin for WordPress is vulnerable to time-based SQL Injection via the ‘sliderid’ parameter in all versions up to, and including, 3.5.1.28 due to insufficient es | Jul 30, 2025 | 4.9 | 19 | NO | NO |
Signals from CVEs in this vendor scope (16 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Nextendweb.
Media articles that mention a CVE ID that affects a product developed by Nextendweb — matched by CVE ID, not by vendor name.