S4E just found a high-severity finding from top 10 tcp port service scan
PlatformPlansPartners
Resources
ToolsBlogDocs
Sign Up →
high·Product Based Web Vulnerabilities·Updated Jun 13, 2024

CVE-2024-2879 Scanner

CVE-2024-2879 scanner - SQL Injection vulnerability in WordPress Plugin LayerSlider

Est. Time~10 seconds
Scan TypeSingle Scan
Targetsdomain, ipv4, subdomain
CostFree
2.2k
Times Used
continuous scan runs
5.9k
Continuously Checked
assets under CS
0
Vulnerabilities Found
confirmed findings
References
CVECVE-2024-2879
9.8
CVSScritical
Exploitable remotely over the internet · no authentication required.

The LayerSlider plugin for WordPress is vulnerable to SQL Injection via the ls_get_popup_markup action in versions 7.9.11 and 7.10.0 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for unauthenticated attackers to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database.

Attack Vector
Network
Privileges Req.
None
User Interaction
None
Affected
LayerSliderby LayerSlider
7.9.11
layersliderby layerslider
AFFECTED< 7.9.12SAFE ✓≥ 7.9.12
layersliderby layerslider
AFFECTED< 7.10.1SAFE ✓≥ 7.10.1
Updated Sep 10, 2026View on NVD →
Detail

LayerSlider is a popular plugin used in WordPress for creating responsive sliders, image galleries, and animated content. It is widely used by website developers and designers to enhance the visual appeal of websites. The plugin is known for its ease of use and rich features, making it a preferred choice among WordPress users. It is often employed in business, personal, and portfolio websites to display content interactively. The plugin's versatility and extensive customization options contribute to its widespread adoption.

The LayerSlider plugin for WordPress contains a SQL Injection vulnerability. This issue arises due to insufficient escaping and lack of preparation on user-supplied parameters in the ls_get_popup_markup action. An attacker can exploit this flaw to inject malicious SQL queries. This could allow unauthorized access to sensitive information from the database. The vulnerability affects versions 7.9.11 and 7.10.0 of the plugin.

The SQL Injection vulnerability in the LayerSlider plugin is found in the ls_get_popup_markup action. This endpoint fails to properly escape user-supplied input and does not adequately prepare SQL queries. Specifically, the id[where] parameter can be manipulated to append additional SQL queries. When exploited, this flaw allows attackers to execute arbitrary SQL commands, which can be used to extract sensitive information from the database. The vulnerability does not require authentication, making it particularly dangerous.

Exploiting this SQL Injection vulnerability can have severe consequences. Attackers could gain unauthorized access to sensitive information stored in the database, such as user credentials and personal data. This can lead to data breaches and compromise the security of the affected websites. Additionally, the vulnerability can be used to manipulate or delete data, disrupt website functionality, and potentially execute further attacks on the web server. The lack of authentication required to exploit this issue amplifies its potential impact.

By becoming a member of the S4E platform, you gain access to comprehensive security scanning tools that help protect your digital assets from vulnerabilities like SQL Injection. Our platform offers detailed reports, actionable insights, and timely alerts to keep your systems secure. With our user-friendly interface and expert support, you can easily manage your cybersecurity risks and ensure the integrity of your web applications. Join S4E today to enhance your cybersecurity posture and safeguard your online presence.

References:

Solution Advice
  • Update the LayerSlider plugin to version 7.10.1 or later.
  • Implement proper input validation and escaping on all user-supplied parameters.
  • Use prepared statements for SQL queries to prevent injection attacks.
  • Regularly monitor and audit your website for potential security vulnerabilities.
  • Consider employing a web application firewall (WAF) to provide additional protection against SQL Injection attacks.

Get AI-powered remediation steps tailored to your asset.

Try AI Solutions →

Check your infrastructure.
Right now.

11,000+ scanners. Free to start. No credit card required.

CVE-2024-2879 scanner - SQL Injection vulnerability in WordPress Plugin LayerSlider | S4E