CVE-2025-60108

8.5

LambertGroup · AllInOne - Banner with Thumbnails

The AllInOne - Banner with Thumbnails WordPress plugin is vulnerable to blind SQL injection, allowing an authenticated user to extract database information through improperly sanitized input parameters.

Executive summary

A blind SQL injection vulnerability in the LambertGroup AllInOne - Banner with Thumbnails plugin allows authenticated attackers to compromise database integrity and confidentiality.

Vulnerability

The software fails to properly neutralize special elements used in SQL commands, resulting in a blind SQL injection vulnerability (CWE-89). Based on the CVSS vector (PR:L), this flaw requires an authenticated user to trigger the malicious query.

Business impact

Successful exploitation of this vulnerability could lead to unauthorized access to sensitive database content, potentially exposing user data or administrative credentials. Given the CVSS score of 8.5, this is a high-severity issue that threatens the confidentiality and stability of the underlying WordPress environment.

Remediation

Immediate Action: As no official patch is currently confirmed, administrators should immediately deactivate and remove the AllInOne - Banner with Thumbnails plugin from their environments until a secure version is released by the vendor.

Proactive Monitoring: Security teams should review web server logs for suspicious database queries, particularly those containing SQL syntax characters or unexpected patterns originating from authenticated user sessions.

Compensating Controls: Deploy a Web Application Firewall (WAF) with rules configured to detect and block common SQL injection patterns to provide a layer of virtual patching against potential exploitation attempts.

Exploitation status

Public Exploit Available: No — there is no confirmed public exploit available in the provided data.

Analyst recommendation

Given the high CVSS score and the potential for database compromise, this vulnerability poses a serious risk to organizational security. Administrators are strongly advised to prioritize the removal of the vulnerable software and monitor for any signs of unauthorized database interaction until the vendor provides a verified security update.

More LambertGroup CVEs

Sources

Originally found and disclosed by João Pedro S Alcântara (Kinorth) | Patchstack Bug Bounty Program, per the CVE Program record.