
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-25371 is a Blind SQL Injection vulnerability in the King-Theme Lumise Product Designer WordPress plugin, classified under CWE-89 (Improper Neutralization of Special Elements used in an SQL Command). It affects all versions of the plugin prior to 2.0.9 and was disclosed on March 25, 2026, with the assigning organization being Patchstack. The vulnerability carries a CVSS v3.1 base score of 9.3 (Critical), reflecting its unauthenticated, network-exploitable nature with high confidentiality impact (Feedly, Patchstack).
The root cause is improper neutralization of user-supplied input in SQL queries within the Lumise Product Designer plugin (CWE-89), enabling Blind SQL Injection attacks. Because the vulnerability requires no authentication, no user interaction, and has low attack complexity, an unauthenticated remote attacker can send crafted HTTP requests to the plugin's endpoints to infer database contents through boolean- or time-based blind injection techniques. The changed scope in the CVSS vector indicates that the impact extends beyond the plugin itself to the underlying WordPress database (Feedly, Patchstack).
Successful exploitation allows unauthenticated attackers to extract sensitive information from the WordPress database, including user credentials, personal information, and other confidential business data. The high confidentiality impact combined with a changed scope means data exposure can extend beyond the plugin's own data to the broader WordPress installation's database contents. Availability is also marginally affected (low availability impact), and while integrity is not directly impacted, exfiltrated credentials could enable follow-on attacks such as account takeover or lateral movement (Feedly).
No public proof-of-concept exploit code has been observed, and there is no evidence of active in-the-wild exploitation at this time. The vulnerability is not currently listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. The EPSS score is approximately 0.021% (0.000210), indicating a low current probability of exploitation in the near term (Feedly).
AND SLEEP(5)-- or conditional expressions) to infer database structure without direct output.sqlmap with the identified endpoint and parameter to enumerate database names, tables, and columns (e.g., sqlmap -u "https://target.com/wp-admin/admin-ajax.php?action=lumise_..." --level=3 --risk=2 --blind).wp_users to retrieve hashed passwords, email addresses, and other sensitive information for offline cracking or further exploitation (Feedly).wp-admin/admin-ajax.php with Lumise-specific action parameters) containing SQL metacharacters (', --, AND, SLEEP, BENCHMARK, OR 1=1).SLEEP() or BENCHMARK() functions originating from the web application user.The vendor (King-Theme) has released a patched version: Lumise Product Designer 2.0.9. All users should immediately upgrade to version 2.0.9 or later via the WordPress plugin dashboard. For installations that cannot be updated immediately, implement web application firewall (WAF) rules to block SQL injection patterns targeting the plugin's endpoints, and restrict access to plugin components at the network level. Monitor application and database logs for suspicious SQL injection patterns as an interim detection measure (Feedly, Patchstack).
The vulnerability was reported and coordinated by Patchstack, a WordPress security platform, and was included in the Wordfence Intelligence Weekly WordPress Vulnerability Report for the week of March 16–22, 2026. No significant independent researcher commentary or broader media coverage has been identified beyond standard vulnerability database listings (Wordfence).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."