NSS A.I CyberSecurity Scoring
NSS
Company Information
Website:http://www.nExtend.nl
Employees number:1
Number of followers:3
NAICS:
Industry Type:Information Technology & Services
Homepage:nExtend.nl
NSS Risk Score (AI oriented)
Between 750 and 799
NSSInformation Technology & Services
Updated:
01/04/2026
01/04/2026
763/1000
Fair
Baa
NSS Global Score (TPRM)
xxxx
NSSInformation Technology & Services
Score locked

NSSFair
Current Score
763Baa (FAIR)
01000
1 incidents
-5 avg impact
Incident timeline with MITRE ATT&CK tactics, techniques, and mitigations.
JULY 2026
763
JUNE 2026
763
MAY 2026
763
APRIL 2026
763
MARCH 2026
763
FEBRUARY 2026
767
Vulnerability
23 Feb 2026 • NSS
Nextend: WordPress Plugin Vulnerability Exposes Sensitive Data From 800,000+ Sites
High-Severity Vulnerability in Smart Slider 3 Plugin Exposes 800,000+ WordPress Sites
762
CRITICAL-5
NEX1774959910
High-Severity Vulnerability in Smart Slider 3 Plugin Exposes 800,000+ WordPress Sites
A critical security flaw (CVE-2026-3098) has been identified in Smart Slider 3, a widely used WordPress plugin with over 800,000 active installations. The vulnerability, classified as an Authenticated Arbitrary File Read, allows attackers with minimal permissions such as subscriber-level access to download sensitive configuration files from affected servers.
The flaw resides in the plugin’s export functionality, specifically within the `actionExportAll()` function of the `ControllerSliders` class. While the feature is designed to compile and export slider assets, it lacks proper capability checks and file validation, enabling attackers to bypass security measures. Exploiting this oversight, threat actors can extract core server files, including the wp-config.php file, which contains database credentials, cryptographic keys, and session salts.
If compromised, this data could allow attackers to escalate privileges, bypass authentication, and gain full control of the targeted website. The risk is heightened for sites with open user registration, as even low-privilege accounts can exploit the flaw.
Security researcher Dmitrii Ignatyev discovered the vulnerability and reported it via the Wordfence Bug Bounty Program on February 23, 2026, earning a $2,208 reward. Wordfence deployed a firewall rule to protect Premium, Care, and Response users on February 24, with free users receiving the update on March 26.
The plugin’s developers, Nextend, released a patched version (3.5.1.34) on March 24, 2026, addressing the issue. Administrators are advised to update immediately to mitigate potential exploitation.
INCIDENT DETAILS -
TYPE
IMPACT
DATA BREACH
REFERENCES
JANUARY 2026
767
DECEMBER 2025
767
NOVEMBER 2025
767
OCTOBER 2025
767
SEPTEMBER 2025
767
AUGUST 2025
767
Frequently Asked Questions
?
What is the current A.I Rankiteo Cyber Score for NSS ??
What was NSS's A.I Rankiteo Cyber Score in June 2026 ??
What was NSS's A.I Rankiteo Cyber Score in May 2026 ??
What was NSS's A.I Rankiteo Cyber Score in April 2026 ??
What was NSS's A.I Rankiteo Cyber Score in March 2026 ??
What was NSS's A.I Rankiteo Cyber Score in February 2026 ??
What was NSS's A.I Rankiteo Cyber Score in January 2026 ??
What was NSS's A.I Rankiteo Cyber Score in December 2025 ??
What was NSS's A.I Rankiteo Cyber Score in November 2025 ??
What was NSS's A.I Rankiteo Cyber Score in October 2025 ??
What was NSS's A.I Rankiteo Cyber Score in September 2025 ??
What was NSS's A.I Rankiteo Cyber Score in August 2025 ??
What is the average per-incident point impact on NSS's A.I Rankiteo Cyber Score over the past 12 months ??
Where can I access detailed records of all cyber incidents associated with NSS ??
Where can I find a summary of the A.I Rankiteo Risk Scoring methodology ??
Where can I view NSS's profile page on Rankiteo ??
How accurate is the A.I Rankiteo Risk Scoring methodology ?