SecAlerts
l

lambertgroup

Security Risk Profile

46
/100
medium

Security Risk Score

Comprehensive risk assessment based on 48 vulnerabilities, EPSS scores, exploitation status, and remediation availability.

📅 Data spans from May 16, 2025 to present

48
Total CVEs
48
Critical+High
0
Exploited
36
Unpatched

Threat Assessment

Avg CVSS
7.6
Base severity
Avg EPSS
0%
Exploit probability
Unpatched
36
Critical/High
Risk Level
46/100
medium

Severity Distribution

Critical
0
High
48
Medium
0
Low
0

Exploit Likelihood

>50% chance
0
20-50%
0
5-20%
0
<5%
7

Age Distribution

Common Weaknesses (CWE)

1
XSS
29
2
SQL Injection
18
3
Path Traversal
2
4
CSRF
1

Most Affected Products

1. LambertGroup Universal Video Player3
2. LambertGroup LBG Zoominoutslider2
3. wordpress/universal-video-player2
4. LambertGroup xPromoter2
5. wordpress/xpromoter2

Recent Vulnerabilities

See more →
CVE-2026-28110
CVSS 7.1EPSS 0%high

WordPress LambertGroup - AllInOne - Banner with Playlist plugin <= 3.8 - Reflected Cross Site Scripting (XSS) vulnerability

Mar 5, 2026🔧 No Patch
CVE-2026-28109
CVSS 7.1EPSS 0%high

WordPress LambertGroup - AllInOne - Content Slider plugin <= 3.8 - Reflected Cross Site Scripting (XSS) vulnerability

Mar 5, 2026🔧 No Patch
CVE-2026-28103
CVSS 7.1EPSS 0%high

WordPress LBG Zoominoutslider plugin <= 5.4.5 - Reflected Cross Site Scripting (XSS) vulnerability

Mar 5, 2026🔧 No Patch
CVE-2026-28108
CVSS 7.1EPSS 0%high

WordPress LambertGroup - AllInOne - Banner with Thumbnails plugin <= 3.8 - Reflected Cross Site Scripting (XSS) vulnerability

Mar 5, 2026🔧 No Patch
CVE-2026-28099
CVSS 7.1EPSS 0%high

WordPress UberSlider Ultra plugin <= 2.3 - Reflected Cross Site Scripting (XSS) vulnerability

Mar 5, 2026🔧 No Patch
CVE-2026-28100
CVSS 7.1EPSS 0%high

WordPress UberSlider PerpetuumMobile plugin <= 2.3 - Reflected Cross Site Scripting (XSS) vulnerability

Mar 5, 2026🔧 No Patch
CVE-2025-69053
CVSS 7.1high

WordPress Universal Video Player plugin <= 3.8.4 - Reflected Cross Site Scripting (XSS) vulnerability

Jan 22, 2026🔧 No Patch
CVE-2025-69048
CVSS 7.1high

WordPress Universal Video Player plugin <= 3.8.4 - Reflected Cross Site Scripting (XSS) vulnerability

Jan 22, 2026🔧 No Patch
CVE-2025-49066
CVSS 7.1high

WordPress Accordion Slider PRO plugin <= 1.2 - Reflected Cross Site Scripting (XSS) vulnerability

Jan 22, 2026🔧 No Patch
CVE-2025-49046
CVSS 7.1high

WordPress xPromoter plugin <= 1.3.4 - Reflected Cross Site Scripting (XSS) vulnerability

Jan 22, 2026🔧 No Patch

Monitor lambertgroup in Real-Time

Get instant alerts when new vulnerabilities are discovered. Stay ahead of security threats with SecAlerts.

Powered bySecAlerts

Monitor Your Software Stack in Real-Time

Get instant alerts when vulnerabilities are discovered in your software stack. Stay ahead of security threats with SecAlerts.

© 2026 SecAlerts Pty Ltd. All rights reserved.

lambertgroup Security Vulnerabilities & Risk Score | 48 CVEs | SecAlerts - SecAlerts