Critical flaw in LayerSlider WordPress plugin impacts 1 million sites
ID: 6286e5ee-d04f-531c-b6a8-5363d2d28174
STIX ID: report--6286e5ee-d04f-531c-b6a8-5363d2d28174
Feed Name: Bleeping Computer
Threat Score
A critical unauthenticated SQL injection (CVE-2024-2879, CVSS 9.8) was discovered in the LayerSlider WordPress plugin (versions 7.9.11–7.10.0) that allows time-based blind extraction of sensitive database data via an unsanitized 'id' parameter; the flaw was reported by researcher AmrAwad, patched by Kreatura Team within 48 hours, and users are advised to upgrade to version 7.10.1.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
