Description
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in LambertGroup xPromoter top_bar_promoter allows Blind SQL Injection.This issue affects xPromoter: from n/a through <= 1.3.4.
Published: 2025-12-16
Score: 8.5 High
EPSS: < 1% Very Low
KEV: No
Impact: Unauthorized data access via blind SQL injection
Action: Immediate Patch
AI Analysis

Impact

This vulnerability allows attackers to execute blind SQL injection through the LambertGroup xPromoter top_bar_promoter plugin, enabling unauthorized access to sensitive data. The flaw arises from improper neutralization of special elements in an SQL command, classified as CWE‑89. Although the injection is blind, it permits manipulation of database queries without visible errors, potentially exposing confidential information.

Affected Systems

LambertGroup’s xPromoter WordPress plugin versions up to 1.3.4 are affected. No other vendors or versions are listed. Users running these versions should verify the plugin version and consider upgrading.

Risk and Exploitability

The vulnerability has a CVSS score of 8.5, indicating high severity, while the EPSS score is less than 1%, reflecting a low probability of exploitation in the wild. The plugin is not listed in the CISA KEV catalog. Based on the description, the likely attack vector is an attacker who can reach the plugin’s input fields—typically through authenticated or privileged site access—and construct SQL queries that exploit the input handling flaw. Because the injection is blind, the attacker may need to infer results via timing or other side‑channel techniques. The high severity warrants immediate remediation.

Generated by OpenCVE AI on April 28, 2026 at 10:13 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade the xPromoter plugin to a version that includes the patch, typically 1.3.5 or newer.
  • Disable or uninstall the xPromoter plugin if upgrading is not feasible.
  • Monitor database queries and logs for unusual activity that may indicate exploitation attempts.

Generated by OpenCVE AI on April 28, 2026 at 10:13 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 23 Apr 2026 15:00:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 8.5, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H'}

cvssV3_1

{'score': 8.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:L'}


Tue, 20 Jan 2026 15:30:00 +0000


Tue, 20 Jan 2026 14:45:00 +0000


Tue, 16 Dec 2025 22:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 16 Dec 2025 21:30:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 8.5, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H'}


Tue, 16 Dec 2025 17:15:00 +0000

Type Values Removed Values Added
First Time appeared Wordpress
Wordpress wordpress
Vendors & Products Wordpress
Wordpress wordpress

Tue, 16 Dec 2025 08:30:00 +0000

Type Values Removed Values Added
Description Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in LambertGroup xPromoter top_bar_promoter allows Blind SQL Injection.This issue affects xPromoter: from n/a through <= 1.3.4.
Title WordPress xPromoter plugin <= 1.3.4 - SQL Injection vulnerability
Weaknesses CWE-89
References

Subscriptions

Wordpress Wordpress
cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published:

Updated: 2026-04-28T16:14:27.776Z

Reserved: 2025-12-15T10:01:11.954Z

Link: CVE-2025-68053

cve-icon Vulnrichment

Updated: 2025-12-16T20:43:56.314Z

cve-icon NVD

Status : Deferred

Published: 2025-12-16T09:16:00.930

Modified: 2026-06-17T09:58:29.503

Link: CVE-2025-68053

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-04-28T10:15:28Z

Weaknesses
  • CWE-89

    Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')