CVE-2025-60108
8.5LambertGroup · AllInOne - Banner with Thumbnails
The AllInOne - Banner with Thumbnails WordPress plugin is vulnerable to blind SQL injection, allowing an authenticated user to extract database information through improperly sanitized input parameters.
Executive summary
A blind SQL injection vulnerability in the LambertGroup AllInOne - Banner with Thumbnails plugin allows authenticated attackers to compromise database integrity and confidentiality.
Vulnerability
The software fails to properly neutralize special elements used in SQL commands, resulting in a blind SQL injection vulnerability (CWE-89). Based on the CVSS vector (PR:L), this flaw requires an authenticated user to trigger the malicious query.
Business impact
Successful exploitation of this vulnerability could lead to unauthorized access to sensitive database content, potentially exposing user data or administrative credentials. Given the CVSS score of 8.5, this is a high-severity issue that threatens the confidentiality and stability of the underlying WordPress environment.
Remediation
Immediate Action: As no official patch is currently confirmed, administrators should immediately deactivate and remove the AllInOne - Banner with Thumbnails plugin from their environments until a secure version is released by the vendor.
Proactive Monitoring: Security teams should review web server logs for suspicious database queries, particularly those containing SQL syntax characters or unexpected patterns originating from authenticated user sessions.
Compensating Controls: Deploy a Web Application Firewall (WAF) with rules configured to detect and block common SQL injection patterns to provide a layer of virtual patching against potential exploitation attempts.
Exploitation status
Public Exploit Available: No — there is no confirmed public exploit available in the provided data.
Analyst recommendation
Given the high CVSS score and the potential for database compromise, this vulnerability poses a serious risk to organizational security. Administrators are strongly advised to prioritize the removal of the vulnerable software and monitor for any signs of unauthorized database interaction until the vendor provides a verified security update.
More LambertGroup CVEs
Sources
Originally found and disclosed by João Pedro S Alcântara (Kinorth) | Patchstack Bug Bounty Program, per the CVE Program record.