CVE-2025-32287: WordPress Responsive HTML5 Audio Player PRO With Playlist plugin <= 3.5.7 - SQL Injection Vulnerability
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in LambertGroup Responsive HTML5 Audio Player PRO With Playlist allows SQL Injection. This issue affects Responsive HTML5 Audio Player PRO With Playlist: from n/a through 3.5.7.
Other sources
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in LambertGroup Responsive HTML5 Audio Player PRO With Playlist lbg-audio2-html5 allows SQL Injection.This issue affects Responsive HTML5 Audio Player PRO With Playlist: from n/a through <= 3.5.7.
— MITRE
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-32287?
CVE-2025-32287 is classified as a critical SQL Injection vulnerability.
How do I fix CVE-2025-32287?
To fix CVE-2025-32287, you should update the Responsive HTML5 Audio Player PRO With Playlist to version 3.5.8 or later.
What causes the CVE-2025-32287 vulnerability?
CVE-2025-32287 is caused by improper neutralization of special elements used in an SQL command.
Which versions are affected by CVE-2025-32287?
CVE-2025-32287 affects versions of Responsive HTML5 Audio Player PRO With Playlist from n/a up to and including 3.5.7.
What type of vulnerability is CVE-2025-32287?
CVE-2025-32287 is an SQL Injection vulnerability that allows an attacker to execute arbitrary SQL commands.