Tagged: LayerSlider, patch, vulnerability
-
AuthorPosts
-
April 2, 2024 at 6:13 pm #1439014
Hello Support,
when do you provide a patched version of the LayerSlider Plugin?
see: https://www.wordfence.com//
also: https://layerslider.com/release-log/Best regards,
jomiApril 3, 2024 at 3:11 am #1439036Please provide an update on the LayerSlider SQL injection vulnerability.
From the CVE, “This vulnerability allows unauthenticated threat actors to inject malicious SQL queries to steal sensitive information from the database.”Additional information.
https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/layerslider/layerslider-7911-7100-unauthenticated-sql-injectionAccording to the Enfold changelog, the latest bundled version is 7.9.11. This vulnerability affects versions 7.9.11 and 7.10.0.
Changelog: https://themeforest.net/item/enfold-responsive-multipurpose-theme/4519990#item-description__changelogApril 3, 2024 at 5:02 am #1439039Hi,
Thank you for the info.
We’ll forward this to our team/channel, and hopefully, we’ll be able to include the latest version of the plugin in the next patch.
Best regards,
IsmaelApril 3, 2024 at 10:19 am #1439063Hello Ismael,
it getting somehow a little bit urging ..
The first pages went down to this unpached plugin. We are not able to update this plugin unless we buy it on top of enfold.
How many days will we have to live with a security leak like this in our systems?Is it possible to deactivate this plugin somehow ??? It is not listed …
Ok Found it — Enfold — Layout Architekt — Bundled Plugins —
Site looks awfull now, but at least its save.
Thanx
-
This reply was modified 1 year, 7 months ago by
Sushipro.
April 3, 2024 at 12:12 pm #1439073Hi,
Yes, you can temporarily disable the plugin in the Enfold > Layout Builder > Layerslider Options settings. The latest version of the plugin will be included in the next patch.
Thank you for your patience.
Best regards,
IsmaelApril 4, 2024 at 3:43 pm #1439206Hey,
Enfold 5.7 is now available: https://kriesi.at/documentation/enfold/changelog/.
Best regards,
Yigit -
This reply was modified 1 year, 7 months ago by
-
AuthorPosts
- You must be logged in to reply to this topic.
