Cybersecurity — 2026-04-10
WordPress Plugin Smart Slider 3 Pro Backdoored via Supply Chain Attack on Nextend Update Servers
Attackers compromised
Analysis
The attack vector, compromising the official update channel rather than exploiting a plugin vulnerability, bypasses all site-level security measures. With 800,000+ installations across the free and Pro editions, the blast radius of even a 6-hour window is substantial. This is the second major WordPress supply chain attack this year, suggesting adversaries are optimizing for maximum distribution over sophistication.
The attack vector, compromising the official update channel rather than exploiting a plugin vulnerability, bypasses all site-level security measures. With 800,000+ installations across the free and Pro editions, the blast radius of even a 6-hour window is substantial. This is the second major WordPress supply chain attack this year, suggesting adversaries are optimizing for maximum distribution over sophistication.