Critical Security Flaw Found in Popular LayerSlider WordPress Plugin

Teilen:

A critical security flaw impacting the LayerSlider plugin for WordPress could be abused to extract sensitive information from databases, such as password hashes.

The flaw, designated as CVE-2024-2879, carries a CVSS score of 9.8 out of a maximum of 10.0. It has been described as a case of SQL injection impacting versions from 7.9.11 through 7.10.0.

The issue has been addressed in version 7.10.1 released on March 27, 2024, following responsible disclosure on March 25. “This update includes important security fixes,” the maintainers of LayerSlider said in their release notes.

LayerSlider is a visual web content editor, a graphic design software, and a digital visual effects that allows users to create animations and rich content for their websites. According to its own site, the plugin is used by “millions of users worldwide.”

The flaw discovered in the tool stems from a case of insufficient escaping of user supplied parameters and the absence of wpdb::prepare(), enabling unauthenticated attackers to append additional SQL queries and glean sensitive information, Wordfence said.

That having said, the way the query is structured limits the attack surface to a time-based approach where an adversary would need to observe the response time of each request to steal information from the database.

The development follows the discovery of an unauthenticated stored cross-site scripting (XSS) flaw in the WP-Members Membership Plugin (CVE-2024-1852, CVSS score: 7.2) that could facilitate the execution of arbitrary JavaScript code. It has been resolved in version 3.4.9.3.

WordPress Security Flaw

The vulnerability, due to insufficient input sanitization and output escaping, “makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page which is the edit users page,” the WordPress security company said.

Should the code be executed in the context of an administrator’s browser session, it can be used to create rogue user accounts, redirect site visitors to other malicious sites, and carry out other attacks, it added.

Over the past few weeks, security vulnerabilities have also been disclosed in other WordPress plugins such as Tutor LMS (CVE-2024-1751, CVSS score: 8.8) and Contact Form Entries (CVE-2024-2030, CVSS score: 6.4) that could be exploited for information disclosure and injecting arbitrary web scripts, respectively.

Ravie Lakshmanan

Kommentar verfassen

Deine E-Mail-Adresse wird nicht veröffentlicht. Erforderliche Felder sind mit * markiert

lade-bild
London, GB
8:30 pm, Juni 24, 2025
Wetter-Symbol 23°C
L: 22° | H: 25°
aufgelockerte Bewölkung
Luftfeuchtigkeit: 65 %
Druck: 1011 mb
Wind: 12 mph SW
Windböe: 24 mph
UV-Index: 0
Niederschlag: 0 mm
Wolken: 40%
Regen Chance: 0%
Sichtbarkeit: 10 km
Sonnenaufgang: 4:43 am
Sonnenuntergang: 9:21 pm
TäglichStündlich
Tägliche VorhersageStündliche Vorhersage
Today 10:00 pm
Wetter-Symbol
22° | 25°°C 0 mm 0% 9 mph 66 % 1011 mb 0 mm/h
Tomorrow 10:00 pm
Wetter-Symbol
17° | 29°°C 0 mm 0% 10 mph 87 % 1013 mb 0 mm/h
Do. Juni 26 10:00 pm
Wetter-Symbol
17° | 25°°C 1 mm 100% 15 mph 79 % 1018 mb 0 mm/h
Fr. Juni 27 10:00 pm
Wetter-Symbol
16° | 28°°C 0 mm 0% 14 mph 65 % 1022 mb 0 mm/h
Sa. Juni 28 10:00 pm
Wetter-Symbol
17° | 29°°C 0 mm 0% 11 mph 80 % 1024 mb 0 mm/h
Today 10:00 pm
Wetter-Symbol
21° | 23°°C 0 mm 0% 9 mph 66 % 1011 mb 0 mm/h
Tomorrow 1:00 am
Wetter-Symbol
18° | 20°°C 0 mm 0% 8 mph 73 % 1012 mb 0 mm/h
Tomorrow 4:00 am
Wetter-Symbol
17° | 17°°C 0 mm 0% 7 mph 87 % 1012 mb 0 mm/h
Tomorrow 7:00 am
Wetter-Symbol
17° | 17°°C 0 mm 0% 7 mph 82 % 1012 mb 0 mm/h
Tomorrow 10:00 am
Wetter-Symbol
24° | 24°°C 0 mm 0% 6 mph 57 % 1013 mb 0 mm/h
Tomorrow 1:00 pm
Wetter-Symbol
26° | 26°°C 0 mm 0% 6 mph 38 % 1012 mb 0 mm/h
Tomorrow 4:00 pm
Wetter-Symbol
29° | 29°°C 0 mm 0% 10 mph 36 % 1010 mb 0 mm/h
Tomorrow 7:00 pm
Wetter-Symbol
27° | 27°°C 0 mm 0% 8 mph 39 % 1009 mb 0 mm/h
Name Preis24H (%)
Bitcoin(BTC)
€90,878.37
2.45%
Ethereum(ETH)
€2,097.87
5.76%
Fesseln(USDT)
€0.86
-0.01%
XRP(XRP)
€1.90
6.97%
Solana(SOL)
€123.76
3.48%
USDC(USDC)
€0.86
0.00%
Dogecoin(DOGE)
€0.141426
4.49%
Shiba Inu(SHIB)
€0.000010
4.34%
Pepe(PEPE)
€0.000009
6.70%
Nach oben scrollen