CVE-2025-60107
Description
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in LambertGroup LambertGroup - AllInOne - Banner with Playlist all-in-one-bannerWithPlaylist allows Blind SQL Injection.This issue affects LambertGroup - AllInOne - Banner with Playlist: from n/a through <= 3.8.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Blind SQL injection in LambertGroup AllInOne Banner with Playlist WordPress plugin allows unauthenticated attackers to extract database contents.
The LambertGroup AllInOne Banner with Playlist WordPress plugin suffers from a blind SQL injection vulnerability due to improper neutralization of special elements used in SQL commands. This affects all versions up to and including 3.8, where unsanitized user input is incorporated into database queries [1].
Exploitation does not require authentication, as the vulnerable parameter is accessible to unauthenticated attackers. By crafting malicious input and observing application responses (such as timing delays or boolean page differences), an attacker can perform blind SQL injection to enumerate database structures and extract data [1].
The impact is severe: an attacker can retrieve sensitive information from the database, including user credentials and other private data. The CVSS v3 base score of 8.5 reflects the high risk, especially given that this type of vulnerability is frequently targeted in mass-exploit campaigns against thousands of WordPress sites [1].
As a mitigation, immediate update of the plugin is strongly recommended. If updating is not possible, administrators should contact their hosting provider or a web developer for assistance. The vulnerability is publicly disclosed with technical details available, making prompt action critical to prevent compromise [1].
AI Insight generated on May 19, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.
Affected products
1- Range: <=3.8
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
1News mentions
0No linked articles in our index yet.