A serious security vulnerability in the WordPress LayerSlider plugin might be leveraged to extract password hashes and other sensitive data from databases.
CVE-2024-2879 is the name of the vulnerability. It has a CVSS score of 9.8 out of a possible 10.0. It has been reported that versions 7.9.11 through 7.10.0 are affected by a SQL injection issue.
Version 7.10.1, which was made available on March 27, 2024, addresses the vulnerability after being responsibly disclosed on March 25. “This update includes important security fixes,” the LayerSlider maintainers stated in their release notes.
Users may create animations and rich content for their websites with LayerSlider, a visual online content editor, graphic design program, and digital visual effects read more Critical Security Flaw Found in Popular LayerSlider WordPress Plugin.
Get up to date on the latest cybersecurity news and enhance your knowledge of cybersecurity with our thorough coverage of the dangers, breaches, and solutions.
