logo

Critical Security Flaw Found in Popular LayerSlider WordPress Plugin

ID: d55e4ff8-1ebe-54ff-8455-2997dddf7c6e

STIX ID: report--d55e4ff8-1ebe-54ff-8455-2997dddf7c6e

Feed Name: The Hacker News

Threat Score
75/100

Date Published: 2024-04-03

Date Updated: 2026-05-05

Author: [email protected] (The Hacker News)

...
...

### Executive summary A critical unauthenticated SQL injection (CVE-2024-2879, CVSS 9.8) was found in the LayerSlider WordPress plugin (affecting versions 7.9.11–7.10.0) that can be abused via time-based SQLi to extract sensitive database data such as password hashes; maintainers released version 7.10.1 to address the issue. The article also notes recent plugin flaws including a stored XSS in WP-Members and other disclosure-level vulnerabilities in Tutor LMS and Contact Form Entries.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.