CVE-2025-31926: WordPress Sticky Radio Player plugin <= 3.4 - SQL Injection Vulnerability
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in LambertGroup Sticky Radio Player allows SQL Injection. This issue affects Sticky Radio Player: from n/a through 3.4.
Other sources
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in LambertGroup Sticky Radio Player lbg-audio5-html5-shoutcaststicky allows SQL Injection.This issue affects Sticky Radio Player: from n/a through <= 3.4.
— MITRE
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-31926?
CVE-2025-31926 has a high severity rating due to its potential for SQL Injection.
How do I fix CVE-2025-31926?
To mitigate CVE-2025-31926, upgrade the Sticky Radio Player to version 3.5 or later.
What type of vulnerability is CVE-2025-31926?
CVE-2025-31926 is an SQL Injection vulnerability that allows improper neutralization of special elements in SQL commands.
Which versions of Sticky Radio Player are affected by CVE-2025-31926?
CVE-2025-31926 affects LambertGroup Sticky Radio Player and WordPress Sticky Radio Player from version 3.4 and below.
What impact does CVE-2025-31926 have on users?
CVE-2025-31926 could allow attackers to execute arbitrary SQL queries on the database, potentially leading to data breaches.