Impact
The vulnerability is an improper neutralization of special elements used in an SQL command, allowing a blind SQL injection attack through the LambertGroup AllInOne Content Slider plugin. Attackers can craft requests that are executed directly against the database, potentially retrieving, modifying, or deleting sensitive data stored by the WordPress site. This type of injection exposes the confidentiality and integrity of database contents without relying on visible error messages.
Affected Systems
Affected systems include WordPress installations that use the LambertGroup AllInOne Content Slider plugin from the earliest release through version 3.8. No specific patch version is listed beyond the upper bound of 3.8, meaning any installation on or before that version is vulnerable.
Risk and Exploitability
The CVSS base score of 8.5 indicates a high severity risk, and while the EPSS score of less than 1% suggests current exploitation probability is low, the vulnerability can be leveraged by an attacker with network or web access to the site. It is not listed in the CISA KEV catalog, but the potential impact remains significant. The attack vector is inferred to be a web-based input to the plugin’s endpoints, as the injection is performed via normal HTTP requests.
OpenCVE Enrichment
EUVD