A critical security flaw was found in the LayerSlider WordPress plugin, which could allow attackers to steal sensitive data from websites. The vulnerability, identified as CVE-2024-2879, affects versions 7.9.11 and 7.10.0 of LayerSlider. It's due to a lack of proper checks on user input, making it possible for attackers to inject malicious SQL code into database queries. This could lead to unauthorized access to databases, including passwords and payment information. The flaw was discovered by a researcher named AmrAwad, who was awarded a $5,500 bounty for finding it. The Kreatura Team, the developers of LayerSlider, quickly released a patch in version 7.10.1 to fix the issue. WordPress sites using LayerSlider are advised to update to the latest version to protect against this vulnerability.
#cybersecurity #wordpress #vulnerability #sqlinjection #cve #plugin #layerslider #AmrAwad