Threat Advisory

WordPress Plugin LayerSlider Addresses SQL Injection Vulnerability

Threat: Vulnerability
Criticality: High
[subscribe_to_unlock_form]

EXECUTIVE SUMMARY:

A critical SQL injection vulnerability tracked as CVE-2024-2879 has been discovered in LayerSlider, a popular premium WordPress plugin used on over one million websites. The flaw of the plugin allows attackers to execute malicious SQL queries, potentially extracting sensitive data from the site's database, including password hashes and user information. While the vulnerability requires no authentication, it is limited to time-based blind SQL injection, where attackers infer data by observing response times. The lack of proper input sanitization exacerbates the issue, as queries are not prepared using WordPress's security functions. The plugin's developers promptly released a security notification to address the vulnerability. It's imperative for WordPress site administrators to prioritize applying this update, alongside general security measures such as keeping plugins updated, disabling unnecessary ones, using strong passwords, and deactivating dormant accounts to mitigate potential risks.[/subscribe_to_unlock_form]

EXECUTIVE SUMMARY:

A critical SQL injection vulnerability tracked as CVE-2024-2879 has been discovered in LayerSlider, a popular premium WordPress plugin used on over one million websites. The flaw of the plugin allows attackers to execute malicious SQL queries, potentially extracting sensitive data from the site's database, including password hashes and user information. While the vulnerability requires no authentication, it is limited to time-based blind SQL injection, where attackers infer data by observing response times. The lack of proper input sanitization exacerbates the issue, as queries are not prepared using WordPress's security functions. The plugin's developers promptly released a security notification to address the vulnerability. It's imperative for WordPress site administrators to prioritize applying this update, alongside general security measures such as keeping plugins updated, disabling unnecessary ones, using strong passwords, and deactivating dormant accounts to mitigate potential risks.[emaillocker id="1283"]

Recommendation:

  • We strongly recommend you update WordPress LayerSlider Plugin to version 7.10.1

REFERENCES:

The following reports contain further technical details:

https://www.bleepingcomputer.com/news/security/critical-flaw-in-layerslider-wordpress-plugin-impacts-1-million-sites/

[/emaillocker]
crossmenu