logo

Critical flaw in LayerSlider WordPress plugin impacts 1 million sites

ID: 6286e5ee-d04f-531c-b6a8-5363d2d28174

STIX ID: report--6286e5ee-d04f-531c-b6a8-5363d2d28174

Feed Name: Bleeping Computer

Threat Score
75/100

Date Published: 2024-04-03

Date Updated: 2026-04-20

Author: Bill Toulas

...
...

A critical unauthenticated SQL injection (CVE-2024-2879, CVSS 9.8) was discovered in the LayerSlider WordPress plugin (versions 7.9.11–7.10.0) that allows time-based blind extraction of sensitive database data via an unsanitized 'id' parameter; the flaw was reported by researcher AmrAwad, patched by Kreatura Team within 48 hours, and users are advised to upgrade to version 7.10.1.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.