Close Menu

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    What's Hot

    Top Cooking Websites For Food Bloggers

    Katy Perry Goes To Space!

    Mr. Meowski’s Bakery To Re-Locate In St. Charles MO

    Facebook X (Twitter) Instagram
    Tech Empire Solutions
    • Home
    • Cloud
    • Cyber Security
    • Technology
    • Business Solution
    • Tech Gadgets
    Tech Empire Solutions
    Home » Critical security vulnerability discovered in popular LayerSlider WordPress plugin
    Cyber Security

    Critical security vulnerability discovered in popular LayerSlider WordPress plugin

    techempireBy techempire5 Comments2 Mins Read
    Facebook Twitter Pinterest Telegram LinkedIn Tumblr WhatsApp Email
    Share
    Facebook Twitter LinkedIn Pinterest Telegram Email

    ReportApril 3, 2024Editorial DepartmentCyber ​​Security/Vulnerabilities

    WordPress Security Vulnerabilities

    A critical security vulnerability affecting the WordPress LayerSlider plugin could be abused to extract sensitive information such as password hashes from the database.

    This flaw is designated CVE-2024-2879 and has a CVSS score of 9.8 out of 10.0. It is described as a SQL injection case affecting versions 7.9.11 through 7.10.0.

    The issue was resolved in version 7.10.1, released on March 27, 2024, following responsible disclosure on March 25. “This update includes important security fixes,” the maintainers of LayerSlider said in their release notes.

    LayerSlider is a visual web content editor, graphic design software, and digital visual effects that allows users to create animations and rich content for their websites. According to its own website, the plugin is used by “millions of users around the world.”

    Internet security

    Wordfence said the flaw found in the tool stems from insufficient escaping of user-supplied parameters and the lack of wpdb::prepare(), allowing an unauthenticated attacker to attach additional SQL queries and collect sensitive information.

    The development follows the discovery of an unauthenticated stored cross-site scripting (XSS) flaw in the WP-Members membership plugin (CVE-2024-1852, CVSS score: 7.2) that could facilitate the execution of arbitrary JavaScript Program code. Resolved in version 3.4.9.3.

    WordPress Security Vulnerabilities

    The WordPress security company said that due to insufficient input sanitization and output escaping, the vulnerability “allows an unauthenticated attacker to inject arbitrary web script into the page, which will be deleted whenever the user visits the injected page (i.e., edit the user page). The script will be executed.”

    It added that if the code is executed in the context of an administrator’s browser session, it could be used to create malicious user accounts, redirect site visitors to other malicious sites, and conduct other attacks.

    Over the past few weeks, security vulnerabilities have been revealed in other WordPress plugins, such as Tutor LMS (CVE-2024-1751, CVSS score: 8.8) and Contact Form Entry (CVE-2024-2030, CVSS score: 6.4) respectively. Used to leak information and inject arbitrary web scripts.

    Did you find this article interesting?follow us Twitter  and LinkedIn to read more exclusive content from us.



    Source link

    Share. Facebook Twitter Pinterest LinkedIn Tumblr Email
    techempire
    • Website

    Related Posts

    Ongoing campaign bombards businesses with spam emails and phone calls

    6 common mistakes organizations make when deploying advanced authentication

    New Chrome zero-day vulnerability CVE-2024-4761 is being actively exploited

    Microsoft patches 61 flaws, including two actively exploited zero-day vulnerabilities

    Dutch court sentences Tornado Cash co-founder to 5 years in prison for money laundering

    Migrate from VMware vSphere to Microsoft Azure

    Leave A Reply Cancel Reply

    Top Reviews
    Editors Picks

    Top Cooking Websites For Food Bloggers

    Katy Perry Goes To Space!

    Mr. Meowski’s Bakery To Re-Locate In St. Charles MO

    Pokémon Trading Card Website Making 100k!

    Legal Pages
    • About Us
    • Disclaimer
    • DMCA
    • Privacy Policy
    Our Picks

    Edufox

    Emerging Academic Education Platforms – Sponsored By Edufox

    GTA 6 Release Date

    Top Reviews

    Type above and press Enter to search. Press Esc to cancel.