Impact
The vulnerability is an SQL Injection flaw in the Lambert Group Sticky HTML5 Music Player plugin for WordPress that allows an attacker to inject arbitrary SQL into database queries.
Affected Systems
All WordPress sites that have installed the lbg-audio3-html5 plugin with a version from the earliest releases through version 3.1.6 are affected, regardless of other plugins or themes.
Risk and Exploitability
The CVSS score of 8.5 indicates high severity, and the EPSS score of <1% denotes a currently low probability of exploitation. The plugin is not listed in CISA’s KEV catalog. Based on the description, the likely attack vector is inferred to be an unauthenticated HTTP request to the plugin’s functionality, where user‑supplied input is not properly sanitized before being incorporated into SQL statements.
OpenCVE Enrichment
EUVD