Hungary
HUN
On 7 April 2026, unauthorized actors gained access to Smart Slider 3 Pro's update infrastructure and made malicious version 3.5.1.35 available through the trusted update system for approximately six hours. The weaponized release could create unauthorized administrator accounts, execute commands, establish persistent backdoors and access credentials on WordPress and Joomla installations. Nextend shut down its update servers, removed the malicious version and released a clean replacement. The compromise of the legitimate vendor update channel constitutes a direct software-supply-chain data-integrity impact.
Estimated severity
75 / 100
Source reliability
90 / 100
Approximate Date
07/04/2026
Targeted Company
NEXTENDWEB
Distribution & Fulfillment
Procurement & Sourcing
Production & Manufacturing
Sales (Retail & Ecommerce)
Warehousing
Service Delivery
Unrecognized Impact
Supply Chain Relations
No information
Hungary
HUN
No other affected countries reported
Target country
Hungary
Affected countries
No information
Impacted regions
No information
Duration
No information
Financial impact (USD M)
No information
Impact types
Affected sectors
Affected departments
Attack types
Attributed threat actors
No information
Incident Sources
Please rotate your phone