Impact
This vulnerability is an improper neutralization of special elements in an SQL command that results in a blind SQL injection flaw in the WordPress LambertGroup AllInOne - Banner with Thumbnails plugin. The flaw allows an attacker to read or modify database contents through unsanitized input, potentially leading to data exfiltration and compromise of site integrity. The weakness is identified as CWE-89.
Affected Systems
All versions of the LambertGroup AllInOne - Banner with Thumbnails plugin through and including version 3.8 are affected. The plugin is provided by LambertGroup and is commonly installed on WordPress sites for banner and thumbnail management.
Risk and Exploitability
The CVSS score of 8.5 indicates high severity. The EPSS score of less than 1% suggests a currently low probability of exploitation, and the vulnerability is not listed in the CISA KEV catalog. Based on the description, the likely attack vector is a web-based exploitation of the plugin’s unsanitized input fields, which can be accessed without authentication or with minimal privilege. An attacker could craft specific input to perform a blind SQL injection, extract sensitive data, or alter site content.
OpenCVE Enrichment
EUVD