CVE-2025-60110
8.5LambertGroup · AllInOne - Banner Rotator
A SQL injection vulnerability in the LambertGroup AllInOne - Banner Rotator plugin allows authenticated attackers to manipulate database queries.
Executive summary
A high-severity SQL injection vulnerability in the LambertGroup AllInOne - Banner Rotator plugin allows authenticated attackers to compromise backend database information.
Vulnerability
The vulnerability is an improper neutralization of special elements used in an SQL command, classified as CWE-89. Based on the CVSS vector PR:L, this flaw requires a low-privileged authenticated user to trigger the injection against the database.
Business impact
The exploitation of this SQL injection vulnerability could lead to unauthorized data exposure, as the attacker may be able to extract sensitive information from the database. Given the CVSS score of 8.5, this represents a significant risk to data confidentiality and potential system stability, necessitating urgent attention to prevent unauthorized access to the underlying application infrastructure.
Remediation
Immediate Action: Since no specific patch version is currently confirmed, administrators should immediately disable or remove the AllInOne - Banner Rotator plugin until a secure update is provided by the vendor.
Proactive Monitoring: Review database query logs for anomalous patterns or unexpected syntax that may indicate automated SQL injection attempts targeting the plugin.
Compensating Controls: Deploy a Web Application Firewall (WAF) with rules configured to detect and block SQL injection patterns to provide a layer of protection if the plugin must remain active.
Exploitation status
Public Exploit Available: Unknown.
Analyst recommendation
Given the high CVSS score, this vulnerability poses a clear risk to the integrity and confidentiality of the host environment. IT administrators are strongly advised to prioritize the removal or containment of the affected plugin until the vendor releases a definitive patch, as SQL injection remains a primary vector for significant data breaches.
More LambertGroup CVEs
Sources
Originally found and disclosed by João Pedro S Alcântara (Kinorth) | Patchstack Bug Bounty Program, per the CVE Program record.