{"id":796,"date":"2024-06-30T22:31:21","date_gmt":"2024-06-30T22:31:21","guid":{"rendered":"https:\/\/www.yellowfalconmedia.com\/blog\/2024\/06\/30\/critical-security-flaw-exposes-1-million-wordpress-sites-to-sql-injection-dark-reading\/"},"modified":"2024-06-30T22:31:21","modified_gmt":"2024-06-30T22:31:21","slug":"critical-security-flaw-exposes-1-million-wordpress-sites-to-sql-injection-dark-reading","status":"publish","type":"post","link":"https:\/\/www.yellowfalconmedia.com\/blog\/2024\/06\/30\/critical-security-flaw-exposes-1-million-wordpress-sites-to-sql-injection-dark-reading\/","title":{"rendered":"Critical Security Flaw Exposes 1 Million WordPress Sites to SQL Injection &#8211; Dark Reading"},"content":{"rendered":"<p>A researcher received a $5,500 bug bounty for discovering a vulnerability (CVE-2024-2879) in LayerSlider, a plug-in with more than a million active installations.<br \/>April 4, 2024<br \/><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">Attackers can exploit a critical SQL injection vulnerability found in a widely used <\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"><a class=\"ContentText-BodyTextChunk ContentText-BodyTextChunk_link\" target=\"_blank\" href=\"https:\/\/www.darkreading.com\/application-security\/wordpress-bug-patch-installs-backdoor-full-site-takeover\" rel=\"noopener\">WordPress plug-in<\/a><\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"> to compromise more than 1 million sites and extract sensitive data such as password hashes from associated databases.<\/span><br \/><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">A security researcher called <\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"><a class=\"ContentText-BodyTextChunk ContentText-BodyTextChunk_link\" target=\"_blank\" href=\"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/researchers\/amrawad\" rel=\"noopener\">AmrAwad<\/a><\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"> (aka 1337_Wannabe) discovered the bug in the LayerSlider, a plug-in for creating animated Web content. The security flaw, tracked as <\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"><a class=\"ContentText-BodyTextChunk ContentText-BodyTextChunk_link\" target=\"_blank\" href=\"https:\/\/www.cve.org\/CVERecord?id=CVE-2024-2879\" rel=\"noopener\">CVE-2024-2879<\/a><\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">, has a rating of 9.8 out of 10 on the CVSS 3.0 vulnerability-severity scale, and is associated with the &quot;ls_get_popup_markup&quot; action in versions 7.9.11 and 7.10.0 of LayerSlider. The vulnerability is due to &quot;insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query,&quot; according to Wordfence.<\/span><br \/><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">&quot;This makes it possible for unauthenticated attackers to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database,&quot; the company said.<\/span><br \/><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">Wordfence awarded the researcher a bounty of $5,500 \u2014 the company&#x27;s highest bounty to date \u2014 for the discovery, according to a <\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"><a class=\"ContentText-BodyTextChunk ContentText-BodyTextChunk_link\" target=\"_blank\" href=\"https:\/\/www.wordfence.com\/blog\/2024\/04\/5500-bounty-awarded-for-unauthenticated-sql-injection-vulnerability-patched-in-layerslider-wordpress-plugin\/\" rel=\"noopener\">blog post<\/a><\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"> by Wordfence. AmrAwad&#x27;s March 25 submission came as part of Wordfence&#x27;s second Bug Bounty Extravaganza, and the company contacted the Kreatura Team, developers of the plug-in, the same day to notify them of the flaw. The team responded the next day and delivered a patch in version 7.10.1 of LayerSlider on March 27.<\/span><br \/><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">The potential for exploitation of the vulnerability lies in the insecure implementation of the LayerSlider plug-in&#x27;s slider popup markup query functionality, which has an &quot;id&quot; parameter, according to Wordfence.<\/span><br \/><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">According to the firm, &quot;if the &#x27;id&#x27; parameter is not a number, it is passed without sanitization to the find() function in the LS_Sliders class,&quot; which &quot;queries the sliders in a way that constructs a statement without the prepare() function.&quot; \u00a0<\/span><br \/><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">Since that function would &quot;parameterize and escape the SQL query for safe execution in WordPress, thereby providing protection against SQL injection attacks,&quot; its absence creates a vulnerable scenario, according to Wordfence.<\/span><br \/><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">However, to exploit the flaw requires a &quot;a time-based blind approach&quot; on the part of attackers to extract database information, which is &quot;an intricate, yet frequently successful method to obtain information from a database when exploiting <\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"><a class=\"ContentText-BodyTextChunk ContentText-BodyTextChunk_link\" target=\"_blank\" href=\"https:\/\/www.darkreading.com\/cyberattacks-data-breaches\/cisa-seeks-to-stem-unforgivable-sql-injection-defects\" rel=\"noopener\">SQL Injection<\/a><\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"> vulnerabilities,&quot; according to Wordfence.<\/span><br \/><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">&quot;This means that they would need to use SQL CASE statements along with the SLEEP() command while observing the response time of each request to steal information from the database,&quot; the company explained.<\/span><br \/><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">Vulnerable <\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"><a class=\"ContentText-BodyTextChunk ContentText-BodyTextChunk_link\" target=\"_blank\" href=\"https:\/\/www.darkreading.com\/cyberattacks-data-breaches\/etherhiding-blockchain-technique-hides-malicious-code-wordpress-sites\" rel=\"noopener\">WordPress sites<\/a><\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"> <\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"><a class=\"ContentText-BodyTextChunk ContentText-BodyTextChunk_link\" target=\"_blank\" href=\"https:\/\/www.darkreading.com\/application-security\/7k-wordpress-sites-compromised-balada-injector\" rel=\"noopener\">are a popular target<\/a><\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"> for attackers given the content management system&#x27;s widespread use across the Internet, and often <\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"><a class=\"ContentText-BodyTextChunk ContentText-BodyTextChunk_link\" target=\"_blank\" href=\"https:\/\/www.darkreading.com\/endpoint-security\/backdoor-lurks-behind-wordpress-caching-plugin-to-hijack-websites\" rel=\"noopener\">vulnerabilities exist in plug-ins<\/a><\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"> that independent developers create for adding functionality to sites using the platform.<\/span><br \/><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">Indeed, at least <\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"><a class=\"ContentText-BodyTextChunk ContentText-BodyTextChunk_link\" target=\"_blank\" href=\"https:\/\/w3techs.com\/technologies\/details\/cm-wordpress\" rel=\"noopener\">43% of websites on the entire Internet<\/a><\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"> use WordPress to power their sites, e-commerce applications, and communities. Further, the wealth of sensitive data such as user passwords and payment info often stored within their pages represents a significant opportunity for threat actors who seek to misuse it.<\/span><br \/><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">Making &quot;the WordPress ecosystem more secure &#8230; ultimately makes the entire web more secure,&quot; WordPress noted.<\/span><br \/><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">Wordfence advised that WordPress users with LayerSlider installed on sites verify immediately that they are updated to the latest, patched version of the plug-in to ensure it isn&#x27;t vulnerable to exploit.<\/span><br \/>Elizabeth Montalbano, Contributing Writer<\/p>\n<p><span class=\"ContentText ContentText_variant_bodyNoneStyle\" data-testid=\"content-text\">Elizabeth Montalbano is a freelance writer, journalist, and therapeutic writing mentor with more than 25 years of professional experience. Her areas of expertise include technology, business, and culture. Elizabeth previously lived and worked as a full-time journalist in Phoenix, San Francisco, and New York City; she currently resides in a village on the southwest coast of Portugal. In her free time, she enjoys surfing, hiking with her dogs, traveling, playing music, yoga, and cooking.<\/span><\/p>\n<p>You May Also Like<br \/>Black Hat USA &#8211; Aug 3-8 &#8211; The Premier Technical Cybersecurity Conference &#8211; Learn More<br \/>Black Hat Europe &#8211; December 9-12 &#8211; Learn More<br \/>SecTor &#8211; Canada&#8217;s IT Security Conference Oct 22-24 &#8211; Learn More<br \/>2024 InformationWeek US IT Salary Report<br \/>Elastic named a Leader in The Forrester Wave\u2122: Security Analytics Platforms, Q4 2022<br \/>2023 Global Threat Report<br \/>EMA: AI at your fingertips: How Elastic AI Assistant simplifies cybersecurity<br \/>The Foundation for Building Scalable Applications to Fuel Customer Satisfaction and Growth<br \/>Data Protection Essentials: Proactive PII Leak Prevention and Data Mapping for GDPR<br \/>How Cyber Threat Intelligence Empowers the C-Suite<br \/>EMA: AI at your fingertips: How Elastic AI Assistant simplifies cybersecurity<br \/>The Cloud Threat Landscape: Security learnings from analyzing 500+ cloud environments<br \/>The Future of Cloud Security: Attack Paths &amp; Graph-based Technology<br \/>Black Hat USA &#8211; Aug 3-8 &#8211; The Premier Technical Cybersecurity Conference &#8211; Learn More<br \/>Black Hat Europe &#8211; December 9-12 &#8211; Learn More<br \/>SecTor &#8211; Canada&#8217;s IT Security Conference Oct 22-24 &#8211; Learn More<br \/><span class=\"CopyrightsSection-TextBlock\"><\/span>Copyright \u00a9 2024 Informa PLC Informa UK Limited is a company registered in England and Wales with company number 1072954 whose registered office is 5 Howick Place, London, SW1P 1WG.<\/p>\n<p><a href=\"https:\/\/news.google.com\/rss\/articles\/CBMiW2h0dHBzOi8vd3d3LmRhcmtyZWFkaW5nLmNvbS9yZW1vdGUtd29ya2ZvcmNlL2NyaXRpY2FsLXNlY3VyaXR5LWZsYXctd29yZHByZXNzLXNxbC1pbmplY3Rpb27SAQA?oc=5\">source<\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p>A researcher received a $5,500 bug bounty for discovering a vulnerability (CVE-2024-2879) in LayerSlider, a plug-in with more than a million active installations.April 4, 2024Attackers can exploit a critical SQL injection vulnerability found in a widely used WordPress plug-in to compromise more than 1 million sites and extract sensitive data&hellip;<\/p>\n","protected":false},"author":2,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"om_disable_all_campaigns":false,"_monsterinsights_skip_tracking":false,"_uf_show_specific_survey":0,"_uf_disable_surveys":false,"footnotes":""},"categories":[1],"tags":[],"class_list":["post-796","post","type-post","status-publish","format-standard","hentry","category-uncategorized"],"aioseo_notices":[],"_links":{"self":[{"href":"https:\/\/www.yellowfalconmedia.com\/blog\/wp-json\/wp\/v2\/posts\/796","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.yellowfalconmedia.com\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.yellowfalconmedia.com\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.yellowfalconmedia.com\/blog\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/www.yellowfalconmedia.com\/blog\/wp-json\/wp\/v2\/comments?post=796"}],"version-history":[{"count":0,"href":"https:\/\/www.yellowfalconmedia.com\/blog\/wp-json\/wp\/v2\/posts\/796\/revisions"}],"wp:attachment":[{"href":"https:\/\/www.yellowfalconmedia.com\/blog\/wp-json\/wp\/v2\/media?parent=796"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.yellowfalconmedia.com\/blog\/wp-json\/wp\/v2\/categories?post=796"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.yellowfalconmedia.com\/blog\/wp-json\/wp\/v2\/tags?post=796"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}