Critical Security Flaw Found in Popular LayerSlider WordPress Plugin
ID: d55e4ff8-1ebe-54ff-8455-2997dddf7c6e
STIX ID: report--d55e4ff8-1ebe-54ff-8455-2997dddf7c6e
Feed Name: The Hacker News
### Executive summary A critical unauthenticated SQL injection (CVE-2024-2879, CVSS 9.8) was found in the LayerSlider WordPress plugin (affecting versions 7.9.11–7.10.0) that can be abused via time-based SQLi to extract sensitive database data such as password hashes; maintainers released version 7.10.1 to address the issue. The article also notes recent plugin flaws including a stored XSS in WP-Members and other disclosure-level vulnerabilities in Tutor LMS and Contact Form Entries.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
