
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2025-67921 is a Blind SQL Injection vulnerability in the VanKarWai Lobo WordPress theme affecting all versions prior to 2.8.6. The flaw was reported by Tran Nguyen Bao Khanh (VCI - VNPT Cyber Immunity) on October 15, 2025, and publicly disclosed by Patchstack on January 5–8, 2026. The CNA (Patchstack) assigned a CVSS v3.1 base score of 8.5 (High), while CISA-ADP initially scored it 9.8 (Critical) before the Patchstack score superseded it (Patchstack).
The vulnerability is classified as CWE-89 (Improper Neutralization of Special Elements used in an SQL Command) and enables Blind SQL Injection attacks against WordPress sites running the Lobo theme. Exploitation requires at minimum Subscriber-level privileges, as indicated by Patchstack's advisory, meaning an attacker must have a low-privilege authenticated account on the target WordPress site. The attack is network-based, requires low complexity, and does not require user interaction, making it straightforward to exploit once the attacker has the required access level (Patchstack). No public proof-of-concept exploit code has been identified at this time (Feedly).
Successful exploitation allows an attacker to execute arbitrary SQL commands against the underlying WordPress database through blind injection techniques. This can result in unauthorized extraction of sensitive data (e.g., user credentials, personal information, configuration data), modification of database contents, and potential disruption of database availability. Because the injection is "blind," attackers infer results through application behavior rather than direct error output, but the impact on confidentiality and integrity remains significant (Patchstack).
No public proof-of-concept exploit or evidence of active in-the-wild exploitation has been reported as of the time of disclosure (Feedly). The EPSS score is approximately 0.021%, indicating a low current probability of exploitation in the near term. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. However, Patchstack notes that vulnerabilities of this class are frequently used in mass-exploit campaigns targeting WordPress sites at scale, regardless of site popularity (Patchstack).
/wp-content/themes/lobo/style.css).SLEEP() or conditional AND 1=1/AND 1=2 logic) to infer database structure and content without direct error output.sqlmap with the identified endpoint and session cookie to automate extraction of database tables, user credentials, and other sensitive data.SLEEP, BENCHMARK, AND 1=, OR 1=) in query parameters or POST bodies; anomalous response time variations suggesting time-based blind injection.%27, %20AND%20, SLEEP%28).SLEEP() or conditional logic; unusual query patterns originating from the WordPress application user.The primary remediation is to update the Lobo WordPress theme to version 2.8.6 or later, which contains the fix for this vulnerability (Patchstack). As a temporary workaround, Patchstack has issued a virtual patching/mitigation rule for subscribers that blocks exploitation attempts until the theme is updated. Additional hardening measures include implementing a Web Application Firewall (WAF), applying the principle of least privilege to database accounts, enforcing input validation, and monitoring database activity for anomalous query patterns.
Wordfence included this vulnerability in their weekly WordPress vulnerability report for January 5–11, 2026, highlighting it as part of broader WordPress ecosystem security coverage (Wordfence). TheHackerWire also covered the disclosure shortly after publication (TheHackerWire). Community reaction has been limited given the absence of active exploitation, but Patchstack's classification of this vulnerability class as prone to mass-exploit campaigns has drawn attention to the need for prompt patching.
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."