The smooth-slider plugin prior to 2.7 for WordPress has SQL Injection via the wp-admin/admin.php?page=smooth-slider-admin current_slider_id parameter.
slidervilla smooth slider