Critical Security Flaw Exposes 1 Million WordPress Sites to SQL Injection
ID: d047a881-7445-53ae-acde-dce040737e85
STIX ID: report--d047a881-7445-53ae-acde-dce040737e85
Feed Name: Dark Reading
Date Published: 2024-04-04
Date Updated: 2026-04-21
Author: Elizabeth Montalbano, Contributing Writer
A critical SQL injection vulnerability (CVE-2024-2879, CVSS 9.8) was found in the LayerSlider WordPress plugin (versions 7.9.11 and 7.10.0) that permits unauthenticated, time-based blind SQLi to extract sensitive database contents; Wordfence reported the bug, awarded a bounty, and the vendor patched the plugin in version 7.10.1 — sites should update immediately to prevent data exfiltration.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
