CVE-2025-60109: WordPress LambertGroup - AllInOne - Content Slider Plugin <= 3.8 - SQL Injection Vulnerability
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in LambertGroup LambertGroup - AllInOne - Content Slider all-in-one-contentSlider allows Blind SQL Injection.This issue affects LambertGroup - AllInOne - Content Slider: from n/a through <= 3.8.
Other sources
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in LambertGroup LambertGroup - AllInOne - Content Slider allows Blind SQL Injection. This issue affects LambertGroup - AllInOne - Content Slider: from n/a through 3.8.
— NVD
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-60109?
CVE-2025-60109 has a high severity rating due to its potential for Blind SQL Injection attacks.
How do I fix CVE-2025-60109?
To fix CVE-2025-60109, update the LambertGroup AllInOne - Content Slider to the latest version beyond 3.8.
What are the potential impacts of CVE-2025-60109?
Exploiting CVE-2025-60109 could allow attackers to access sensitive database information through SQL injection.
Which versions are affected by CVE-2025-60109?
CVE-2025-60109 affects LambertGroup AllInOne - Content Slider from any version up to and including 3.8.
Is CVE-2025-60109 related to WordPress?
Yes, CVE-2025-60109 also affects the WordPress AllInOne - Content Slider Plugin up to version 3.8.