A critical vulnerability in the WordPress plugin LayerSlider could be used to extract sensitive information (e.g. password hashes) from databases.

The vulnerability is tracked as CVE-2024-2879 (CVSS score 9.8/10). It is a SQL injection vulnerability affecting LayerSlider versions 7.9.11 to 7.10.0.
The issue was addressed in version 7.10.1 released on March 27, 2024. “ This update includes important security fixes ,” LayerSlider maintainers said
See also: New Sign1 malware has infected thousands of WordPress sites
LayerSlider is a visual web content editor, graphic design software, and digital visual effects plugin that allows users to create animations and rich content for their WordPress sites. The plugin is used by “millions of users worldwide.”
The vulnerability allows unauthenticated attackers to append additional SQL queries and collect sensitive information.
Importance of WordPress protection
Protecting WordPress websites is especially important for many reasons. First, WordPress websites are very popular, which means they are a prime target for cybercriminals. If your website is not protected, significant damage can occur.

See also: Popup Builder plugin: Vulnerability puts thousands of WordPress sites at risk
Additionally, an unsecured WordPress site can undermine the trust and credibility you’ve built with customers your. If their data is compromised, they’re more likely to sue you and switch to other companies.
Securing your website is also important for maintaining the consistency and credibility of your content. If a hacker breaks into your website and corrupts the content, it can give the impression that you are not doing enough with your website.
See also: WordPress sites use visitor browsers to hack other sites
In other words, ensuring your WordPress website is secure isn’t just about protecting your data – it’s about maintaining your customers ’ trust , preserving your company’s reputation, and staying on top of the competition.
Source: thehackernews.com
🔒 Protect your privacy with Proton VPN
Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.
- ✔ No-logs, based in Switzerland (except 14-Eyes)
- ✔ NetShield: blocks ads, trackers & malicious domains
- ✔ Covers all devices — free version available
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
