CVE-2025-60108: WordPress LambertGroup - AllInOne - Banner with Thumbnails Plugin <= 3.8 - SQL Injection Vulnerability
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in LambertGroup LambertGroup - AllInOne - Banner with Thumbnails all-in-one-thumbnailsBanner allows Blind SQL Injection.This issue affects LambertGroup - AllInOne - Banner with Thumbnails: from n/a through <= 3.8.
Other sources
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in LambertGroup LambertGroup - AllInOne - Banner with Thumbnails allows Blind SQL Injection. This issue affects LambertGroup - AllInOne - Banner with Thumbnails: from n/a through 3.8.
— NVD
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-60108?
CVE-2025-60108 is considered a high-severity vulnerability due to its potential for SQL injection attacks.
What software is affected by CVE-2025-60108?
CVE-2025-60108 affects LambertGroup - AllInOne - Banner with Thumbnails versions up to 3.8 and WordPress AllInOne - Banner with Thumbnails Plugin versions up to 3.8.
How do I fix CVE-2025-60108?
To fix CVE-2025-60108, update the LambertGroup - AllInOne - Banner with Thumbnails and WordPress AllInOne - Banner with Thumbnails Plugin to the latest version.
What type of vulnerability is CVE-2025-60108?
CVE-2025-60108 is identified as an SQL Injection vulnerability, specifically a Blind SQL Injection.
Can CVE-2025-60108 lead to data breaches?
Yes, CVE-2025-60108 can allow attackers to manipulate database queries, potentially leading to data breaches.