CVE-2025-60107
8.5LambertGroup · AllInOne - Banner with Playlist
A SQL injection vulnerability in the LambertGroup AllInOne - Banner with Playlist plugin allows authenticated attackers to perform blind SQL injection attacks.
Executive summary
A high-severity blind SQL injection vulnerability exists in the LambertGroup AllInOne - Banner with Playlist plugin, posing a significant risk of unauthorized database data exposure.
Vulnerability
The plugin fails to properly neutralize special elements used in SQL commands, resulting in a blind SQL injection vulnerability. Based on the CVSS vector, this flaw requires the attacker to have low-level privileges (authenticated) to trigger the malicious query.
Business impact
Successful exploitation of this vulnerability allows an authenticated attacker to extract sensitive information from the underlying database, potentially leading to unauthorized data disclosure. Given the CVSS score of 8.5, this high-severity flaw could facilitate credential theft or further compromise of the WordPress environment, resulting in significant operational and reputational damage.
Remediation
Immediate Action: As no specific patch version is currently identified, users should immediately deactivate and remove the AllInOne - Banner with Playlist plugin until a secure update is released by the vendor.
Proactive Monitoring: Review database query logs for unusual patterns or syntax errors that suggest automated injection attempts against the plugin's endpoints.
Compensating Controls: Implement a Web Application Firewall (WAF) with rules configured to detect and block common SQL injection patterns until the vulnerable code is updated or removed.
Exploitation status
Public Exploit Available: No (exploit_available: false)
Analyst recommendation
This vulnerability represents a high risk to the confidentiality of the database and requires immediate attention. Organizations utilizing the LambertGroup AllInOne - Banner with Playlist plugin should treat this as a high-priority incident and remove the affected component from their environment until the vendor provides a verified security update.
More LambertGroup CVEs
Sources
Originally found and disclosed by João Pedro S Alcântara (Kinorth) | Patchstack Bug Bounty Program, per the CVE Program record.