CVE-2026-28108: WordPress LambertGroup - AllInOne - Banner with Thumbnails plugin <= 3.8 - Reflected Cross Site Scripting (XSS) vulnerability
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in LambertGroup LambertGroup - AllInOne - Banner with Thumbnails all-in-one-thumbnailsBanner allows Reflected XSS.This issue affects LambertGroup - AllInOne - Banner with Thumbnails: from n/a through <= 3.8.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-28108?
CVE-2026-28108 has a high severity rating due to its reflected Cross Site Scripting (XSS) vulnerability that can lead to unauthorized actions by attackers.
How do I fix CVE-2026-28108?
To fix CVE-2026-28108, update the LambertGroup - AllInOne - Banner with Thumbnails plugin to version 3.9 or later, which addresses this vulnerability.
What kind of attacks can CVE-2026-28108 enable?
CVE-2026-28108 can enable attackers to execute malicious scripts in the context of the user's session, potentially compromising user data or performing unauthorized actions.
Who is affected by CVE-2026-28108?
CVE-2026-28108 affects users of the LambertGroup - AllInOne - Banner with Thumbnails plugin version 3.8 and earlier on WordPress.
When was CVE-2026-28108 disclosed?
CVE-2026-28108 was disclosed in 2026, making it critical for users to promptly apply updates to mitigate the risk.