Netskope Threat Labs

SERVER-WEBAPP Unauthenticated remote code execution via compromised Smart Slider WordPress plugin detected

IPS-NPA

1 SID: 300062

Detects exploitation of a compromised Smart Slider WordPress plugin installation that runs operator-supplied code without authentication. Sites running the tampered plugin act as open backdoors, so this signature marks an already-compromised WordPress host.