PT-2025-44270 · WordPress · Thumbnail Slider With Lightbox

Published

2025-10-29

·

Updated

2025-12-19

·

CVE-2015-10146

CVSS v3.1

4.9

Medium

VectorAV:N/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions Thumbnail Slider With Lightbox versions up to and including 1.0.4
Description The Thumbnail Slider With Lightbox plugin for WordPress is susceptible to SQL Injection through the id parameter. Insufficient escaping of user-supplied input and inadequate preparation of existing SQL queries allow authenticated attackers with Administrator-level access or higher to inject additional SQL queries. This can lead to the extraction of sensitive information from the database.
Recommendations Versions prior to 1.0.5 are affected. Update to version 1.0.5 or later to address this issue.

Fix

SQL injection

Weakness Enumeration

Related Identifiers

CVE-2015-10146

Affected Products

Thumbnail Slider With Lightbox