logo

Critical Security Flaw Exposes 1 Million WordPress Sites to SQL Injection

ID: d047a881-7445-53ae-acde-dce040737e85

STIX ID: report--d047a881-7445-53ae-acde-dce040737e85

Feed Name: Dark Reading

Threat Score
75/100

Date Published: 2024-04-04

Date Updated: 2026-04-21

Author: Elizabeth Montalbano, Contributing Writer

...
...

A critical SQL injection vulnerability (CVE-2024-2879, CVSS 9.8) was found in the LayerSlider WordPress plugin (versions 7.9.11 and 7.10.0) that permits unauthenticated, time-based blind SQLi to extract sensitive database contents; Wordfence reported the bug, awarded a bounty, and the vendor patched the plugin in version 7.10.1 — sites should update immediately to prevent data exfiltration.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.