Netskope Threat Labs

SERVER-WEBAPP Authenticated remote code execution via compromised Smart Slider WordPress plugin detected

IPS-NPA

1 SID: 300063

Detects exploitation of a compromised Smart Slider WordPress plugin installation that runs operator-supplied code through its server components. Sites running the tampered plugin act as backdoors, so this signature marks an already-compromised WordPress host rather than a single vulnerability.