mySites.guru - WordPress & Joomla Site Manager
Smart Slider 3 Pro version 3.5.1.35 was a malicious release. Pushed through the official Nextend update infrastructure by an unauthorized party, it contained a remote code execution backdoor that runs shell commands or PHP on demand. The trigger is a single query parameter matched against a secret stored in the database. This affects both the WordPress and Joomla versions of Smart Slider 3 Pro. mySites.guru is already discovering this backdoor on live client sites in the wild. Our suspect content scanner caught six separate backdoor patterns in a single 16-line file from one real infected client, including persistence tricks Nextend's own advisory does not mention. Update to 3.5.1.36 immediately. If your site ran 3.5.1.35 at any point, search for hidden admin users starting with wpsvc_ and PHP files named cf_check.php in /cache and /media. Full breakdown on the blog. https://mysites.guru/blog/smart-slider-3-pro-supply-chain-compromise/?utm_source=facebook&utm_medium=social