Security News > 2024 > April > Critical flaw in LayerSlider WordPress plugin impacts 1 million sites

Critical flaw in LayerSlider WordPress plugin impacts 1 million sites
2024-04-03 18:21

A premium WordPress plugin named LayerSlider, used in over one million sites, is vulnerable to unauthenticated SQL injection, requiring admins to prioritize applying security updates for the plugin.

LayerSlider is a versatile tool for creating responsive sliders, image galleries, and animations on WordPress sites, allowing users to build visually appealing elements with dynamic content on online platforms.

The flaw, which impacts versions 7.9.11 through 7.10.0 of the plugin, could allow attackers to extract sensitive data, such as password hashes, from the site's database, putting them at risk of complete takeover or data breaches.

Hackers exploit WordPress plugin flaw to infect 3,300 sites with malware.

Evasive Sign1 malware campaign infects 39,000 WordPress sites.

Hackers exploit critical RCE flaw in Bricks WordPress site builder.


News URL

https://www.bleepingcomputer.com/news/security/critical-flaw-in-layerslider-wordpress-plugin-impacts-1-million-sites/

Related vendor

VENDOR LAST 12M #/PRODUCTS LOW MEDIUM HIGH CRITICAL TOTAL VULNS
Wordpress 49 36 409 104 29 578
Plugin 2 0 13 0 0 13