Critical Security Flaw Exposes 1 Million WordPress Sites to SQL Injection

April 4, 2024 at 11:46AM A researcher was awarded a $5,500 bug bounty for identifying a vulnerability (CVE-2024-2879) in LayerSlider, a widely used plug-in with over a million active installations. The meeting notes indicate that a researcher received a $5,500 bug bounty for discovering a vulnerability (CVE-2024-2879) in LayerSlider, a plug-in with more than a … Read more

Critical flaw in LayerSlider WordPress plugin impacts 1 million sites

April 3, 2024 at 02:28PM LayerSlider, a popular WordPress plugin with over one million users, has been found to be vulnerable to unauthenticated SQL injection, allowing attackers to extract sensitive data from websites. Researcher AmrAwad received a $5,500 bounty for reporting this critical flaw, which has been addressed by the release of version 7.10.1, requiring … Read more

Critical Vulnerability Found in LayerSlider Plugin Installed on a Million WordPress Sites

April 3, 2024 at 09:18AM A critical SQL injection vulnerability in the LayerSlider plugin, tracked as CVE-2024-2879 with a CVSS score of 9.8, allows unauthenticated attackers to extract sensitive information from website databases. The issue was reported through Defiant’s bug bounty program, and a $5,500 reward was given to the reporting researcher. Users are advised … Read more

Critical Security Flaw Found in Popular LayerSlider WordPress Plugin

April 3, 2024 at 02:03AM A critical security flaw (CVE-2024-2879) in LayerSlider plugin for WordPress, with a CVSS score of 9.8, could lead to information extraction from databases. The vulnerability, fixed in version 7.10.1, arose from SQL injection and could allow unauthenticated attackers to manipulate SQL queries. Other WordPress plugins have also disclosed security vulnerabilities … Read more