Impact
Improper neutralization of special elements in SQL commands allows a blind SQL injection attack in the LambertGroup AllInOne - Banner with Playlist plugin. An attacker can craft input that causes the plugin to execute arbitrary SQL statements against the WordPress database. The vulnerability can reveal sensitive data or alter the database, compromising confidentiality and integrity, and may enable privilege escalation if the database user privileges are high.
Affected Systems
Lambert Group’s AllInOne - Banner with Playlist plugin is affected for all versions up to and including 3.8. Any WordPress installation using this plugin, regardless of site tier, is potentially vulnerable.
Risk and Exploitability
The CVSS score of 8.5 classifies this as a high‑severity flaw, while the EPSS score of less than 1% suggests a low probability of exploitation currently. The vulnerability is not listed in KEV, indicating no known widespread exploitation. The likely attack vector is through the plugin’s input endpoints, where a remote attacker can submit malicious payloads without needing authenticated access. Because it is a blind injection, exploitation requires observation of side effects such as response timing or error messages, but once successful it can lead to data retrieval or modification.
OpenCVE Enrichment
EUVD