CVE-2025-60109
8.5LambertGroup · AllInOne - Content Slider
The LambertGroup AllInOne - Content Slider plugin for WordPress is vulnerable to Blind SQL Injection, allowing an authenticated attacker to manipulate database queries.
Executive summary
A Blind SQL Injection vulnerability in the LambertGroup AllInOne - Content Slider plugin allows authenticated attackers to potentially exfiltrate sensitive data from the database.
Vulnerability
This flaw is a Blind SQL Injection (CWE-89) triggered by improper neutralization of special elements in SQL commands. The vulnerability requires the attacker to have at least low-level authenticated access to the system.
Business impact
The ability to perform Blind SQL Injection poses a significant risk to data confidentiality, as attackers can extract information from the database through inference. Given the CVSS score of 8.5, this high-severity vulnerability could lead to unauthorized data disclosure and potential compromise of the underlying application integrity.
Remediation
Immediate Action: Since no specific patch version is currently identified, administrators should immediately deactivate or remove the AllInOne - Content Slider plugin until a security update is released by the vendor.
Proactive Monitoring: Review database error logs and query execution logs for unusual patterns, such as unexpected syntax errors or high volumes of time-based query requests.
Compensating Controls: Deploy a Web Application Firewall (WAF) with rules configured to detect and block common SQL injection patterns targeting the WordPress environment.
Exploitation status
Public Exploit Available: Unknown.
Analyst recommendation
Due to the high CVSS severity and the nature of SQL injection flaws, this vulnerability presents a substantial risk to organizational data. Organizations currently utilizing the LambertGroup AllInOne - Content Slider should prioritize its removal or deactivation until the vendor provides a verified security patch to remediate the underlying code vulnerability.
More LambertGroup CVEs
Sources
Originally found and disclosed by João Pedro S Alcântara (Kinorth) | Patchstack Bug Bounty Program, per the CVE Program record.