Vulnerability on LayerSlider Plugin - WordPress
Incident Report for Liquid Web - Services
Resolved
This has been resolved.
Posted Apr 04, 2024 - 13:07 EDT
Update
All users of the LayerSlider Plugin are strongly encouraged to upgrade to version 7.10.1, where the vulnerability is patched in the plugin code itself.

We appreciate your patience in the matter and if you have any questions, please contact a member of our support team via live-chat, ticket, or by phone at (800)-580-4985, (517)-322-0434 (international).
Posted Apr 04, 2024 - 08:23 EDT
Identified
Our team has been made aware of a vulnerability in the LayerSlider Plugin used on WordPress.

The LayerSlider plugin for WordPress is vulnerable to SQL Injection via the ls_get_popup_markup action in versions 7.9.11 and 7.10.0 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for unauthenticated attackers to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database.

More information can be found here: https://www.wordfence.com/blog/2024/04/5500-bounty-awarded-for-unauthenticated-sql-injection-vulnerability-patched-in-layerslider-wordpress-plugin/

All users of the LayerSlider Plugin are strongly encouraged to upgrade to version 7.10.1, which has the issue fixed.

We appreciate your patience in the matter and if you have any questions, please contact a member of our support team via live-chat, ticket, or by phone at (800)-580-4985, (517)-322-0434 (international).
Posted Apr 03, 2024 - 13:29 EDT