File read flaw in Smart Slider plugin impacts 500K WordPress sites

2026-03-29T19:23:30Zbac9fe1783a338c46ea556b926ab72863431ad5cabd3a668c2d73ab85f43a12d
amazon-awsarbitrary-file-readcisacloud-breachfile-readgithubinfinity-stealerinfoseclangflowmacosmalwarenuitkaphishingpypipythonsanctionssmart-slidersocial-engineeringsupply-chaintelnyxtik-tokwav-steganographyweb-applicationwordpressxinbi

What happened

This collection highlights multiple high-impact security events: a file-read vulnerability in the Smart Slider 3 WordPress plugin (reported to affect hundreds of thousands of sites) that allows subscriber-level accounts to read arbitrary files on servers; a new macOS info-stealer called Infinity Stealer delivering a Python/Nuitka-packed payload; a supply-chain compromise of the Telnyx PyPI package that pushed credential-stealing malware hidden in a WAV file; and a GitHub campaign using fake VS Code alerts to trick developers into downloading malware. Additional notable items include CISA’s警告on

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
bleepingcomputer
Record identifier
bac9fe1783a338c46ea556b926ab72863431ad5cabd3a668c2d73ab85f43a12d
Enrichment time
2026-03-29T19:23:30Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.