Input validation vulnerability in LayerSlider 6.2.0

The LayerSlider plugin for WordPress has a security vulnerability in all versions up to 6.2.0. An attacker can exploit this vulnerability to create an administrative account without the site administrator’s knowledge. They can do this by tricking the administrator into clicking on a malicious link. Once they have access, they could use an SQLi attack to cause further damage to the site. The problem is caused by the ls_save_screen_options() function not properly validating nonce authentication.

Detected in:

LayerSlider fixed vulnerable versions: >= * <= 6.2.0

This information is sourced from www.wpvulnerability.com. An open-source database of vulnerabilities maintained by the community. Help us out by submitting vulnerabilities!

Version compare shows which versions have a vulnerability. For example: >= 2.2.8 <= 2.2.21 means:

> from 2.2.8
= including 2.2.8 & 2.2.21
< to 2.2.21

Is this information incorrect? Please leave us a message.