CVE-2025-60107: WordPress LambertGroup - AllInOne - Banner with Playlist Plugin <= 3.8 - SQL Injection Vulnerability
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in LambertGroup LambertGroup - AllInOne - Banner with Playlist all-in-one-bannerWithPlaylist allows Blind SQL Injection.This issue affects LambertGroup - AllInOne - Banner with Playlist: from n/a through <= 3.8.
Other sources
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in LambertGroup LambertGroup - AllInOne - Banner with Playlist allows Blind SQL Injection. This issue affects LambertGroup - AllInOne - Banner with Playlist: from n/a through 3.8.
— NVD
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-60107?
CVE-2025-60107 is classified as a critical SQL Injection vulnerability.
How do I fix CVE-2025-60107?
To fix CVE-2025-60107, update the LambertGroup - AllInOne - Banner with Playlist to version 3.9 or later.
What are the risks associated with CVE-2025-60107?
The risks of CVE-2025-60107 include unauthorized access to sensitive data and potential full server compromise through Blind SQL Injection.
Which versions are affected by CVE-2025-60107?
CVE-2025-60107 affects LambertGroup - AllInOne - Banner with Playlist versions up to 3.8.
Is CVE-2025-60107 exploitable remotely?
Yes, CVE-2025-60107 is exploitable remotely, allowing attackers to execute SQL commands through the application.