Description
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in VanKarWai Lobo lobo allows Blind SQL Injection.This issue affects Lobo: from n/a through < 2.8.6.
Published: 2026-01-08
Score: 8.5 High
EPSS: < 1% Very Low
KEV: No
Impact: SQL Injection
Action: Patch
AI Analysis

Impact

The vulnerability is an Improper Neutralization of Special Elements used in an SQL Command, classified as CWE-89, that allows blind SQL injection in the VanKarWai Lobo WordPress theme. Attackers could manipulate untrusted input to alter SQL queries, potentially extracting sensitive data or modifying database contents. The worst‑case impact is data compromise and, depending on the database environment, possible elevation of privileges or execution of arbitrary code if the injected payload is later interpreted as a statement with elevated rights.

Affected Systems

Affected are installations of the Lobo theme from VanKarWai, specifically versions from the first release through any version prior to 2.8.6. Any WordPress site using those theme versions is vulnerable unless the theme has been updated beyond the stated cutoff.

Risk and Exploitability

The CVSS score of 8.5 indicates high severity, while the EPSS score of less than 1% suggests that the likelihood of a successful exploit is low but not impossible. The vulnerability is not listed in CISA’s KEV catalog, implying no known widespread exploitation at present. The attack vector is inferred to be via web‑based inputs processed by the theme—such as forum posts, comments, or custom forms—where malicious payloads can be injected into SQL queries.

Generated by OpenCVE AI on April 28, 2026 at 18:18 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade the Lobo theme to version 2.8.6 or later immediately.
  • If an upgrade is not feasible, deactivate or remove the Lobo theme from the site to eliminate the attack surface.
  • Implement input validation and parameterized queries on any custom code that interacts with the database to avoid repeating this weakness.

Generated by OpenCVE AI on April 28, 2026 at 18:18 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 27 Apr 2026 19:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 23 Apr 2026 15:00:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 9.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'}

cvssV3_1

{'score': 8.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:L'}


Tue, 20 Jan 2026 15:30:00 +0000


Tue, 20 Jan 2026 14:45:00 +0000


Fri, 09 Jan 2026 13:30:00 +0000

Type Values Removed Values Added
First Time appeared Wordpress
Wordpress wordpress
Vendors & Products Wordpress
Wordpress wordpress

Thu, 08 Jan 2026 18:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Thu, 08 Jan 2026 16:30:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 9.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'}


Thu, 08 Jan 2026 09:45:00 +0000

Type Values Removed Values Added
Description Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in VanKarWai Lobo lobo allows Blind SQL Injection.This issue affects Lobo: from n/a through < 2.8.6.
Title WordPress Lobo theme < 2.8.6 - SQL Injection vulnerability
Weaknesses CWE-89
References

Subscriptions

Wordpress Wordpress
cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published:

Updated: 2026-04-28T16:14:23.676Z

Reserved: 2025-12-15T09:59:49.436Z

Link: CVE-2025-67921

cve-icon Vulnrichment

Updated: 2026-01-08T14:55:20.811Z

cve-icon NVD

Status : Deferred

Published: 2026-01-08T10:15:51.100

Modified: 2026-04-27T18:16:49.207

Link: CVE-2025-67921

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-04-28T18:30:37Z

Weaknesses