SQL Injection Vulnerability in LambertGroup Radio Player Shoutcast & Icecast Plugin
CVE-2025-32306
8.5HIGH
Key Information:
- Vendor
WordPress
- Vendor
- CVE Published:
- 16 May 2025
What is CVE-2025-32306?
A vulnerability has been identified in the LambertGroup Radio Player Shoutcast & Icecast WordPress Plugin, which allows for SQL Injection through improper neutralization of special elements in SQL commands. This flaw can be exploited to execute blind SQL queries, potentially compromising the integrity of the database and exposing sensitive information stored in it. Users of the impacted versions should update their plugins to mitigate this risk and protect their WordPress sites from potential attacks.
Affected Version(s)
Radio Player Shoutcast & Icecast WordPress Plugin <= 4.4.6
References
CVSS V3.1
Score:
8.5
Severity:
HIGH
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Changed
Timeline
Vulnerability published
Vulnerability Reserved
Credit
Tran Nguyen Bao Khanh (VCI - VNPT Cyber Immunity) (Patchstack Alliance)