Revolution slider security vulnerabilty!
I recieved this email from Sucuri Security:
We’re emailing you to alert you to a serious vulnerability in the WordPress Slider Revolution premium plugin. The developer behind the popular plugin patched the vulnerability silently, meaning that, if you are running WordPress Slider Revolution, you have probably not yet heard that you must update as soon as possible.
This is a very serious vulnerability known as a Local File Inclusion (LFI) attack. It allows a user to retrieve data from files on your server. An example of such an attack would be pulling your WordPress
wp-config.php file and using the credentials in that file to exploit your database and gain access to your website. If you use this plugin, please update immediately. If you’d like to learn more about the vulnerability, you can read about it on our blog.
Clients using our Website Firewall product are already being protected against this vulnerability.
--Your Security Team
Will this be addressed in the next release?
Even though The Sucuri Firewall has my site covered, tech support still recommends updating ASAP!