logo

WordPress LayerSlider Plugin: SQL Injection Vulnerability

ID: a5d8f28b-d7ae-5f71-b6b9-b5f178e1a84f

STIX ID: report--a5d8f28b-d7ae-5f71-b6b9-b5f178e1a84f

Feed Name: Qualys Blog

Threat Score
70/100

Date Published: 2024-04-22

Date Updated: 2026-04-28

Author: Hitesh Kadu

...
...

Qualys reported CVE-2024-2879 on 2024-03-25: an unauthenticated SQL injection in the LayerSlider WordPress plugin (versions 7.9.11–7.10.0, CVSS 7.5). The report includes vulnerable code excerpts, a proof-of-concept payload, detection guidance via QID 150868 in Qualys Web Application Scanning, and advises upgrading to LayerSlider 7.10.1 to remediate the issue.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.