CVE-2026-25371: 
WordPress vulnerability analysis and mitigation

Overview

CVE-2026-25371 is a Blind SQL Injection vulnerability in the King-Theme Lumise Product Designer WordPress plugin, classified under CWE-89 (Improper Neutralization of Special Elements used in an SQL Command). It affects all versions of the plugin prior to 2.0.9 and was disclosed on March 25, 2026, with the assigning organization being Patchstack. The vulnerability carries a CVSS v3.1 base score of 9.3 (Critical), reflecting its unauthenticated, network-exploitable nature with high confidentiality impact (Feedly, Patchstack).

Technical details

The root cause is improper neutralization of user-supplied input in SQL queries within the Lumise Product Designer plugin (CWE-89), enabling Blind SQL Injection attacks. Because the vulnerability requires no authentication, no user interaction, and has low attack complexity, an unauthenticated remote attacker can send crafted HTTP requests to the plugin's endpoints to infer database contents through boolean- or time-based blind injection techniques. The changed scope in the CVSS vector indicates that the impact extends beyond the plugin itself to the underlying WordPress database (Feedly, Patchstack).

Impact

Successful exploitation allows unauthenticated attackers to extract sensitive information from the WordPress database, including user credentials, personal information, and other confidential business data. The high confidentiality impact combined with a changed scope means data exposure can extend beyond the plugin's own data to the broader WordPress installation's database contents. Availability is also marginally affected (low availability impact), and while integrity is not directly impacted, exfiltrated credentials could enable follow-on attacks such as account takeover or lateral movement (Feedly).

Exploitability

No public proof-of-concept exploit code has been observed, and there is no evidence of active in-the-wild exploitation at this time. The vulnerability is not currently listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. The EPSS score is approximately 0.021% (0.000210), indicating a low current probability of exploitation in the near term (Feedly).

Exploitation steps

  1. Reconnaissance: Identify WordPress sites running the Lumise Product Designer plugin (versions < 2.0.9) using tools like WPScan, Shodan, or by inspecting plugin directories exposed via the target site.
  2. Identify injectable endpoint: Probe the plugin's publicly accessible endpoints or parameters that interact with the database to locate those susceptible to SQL injection.
  3. Craft blind SQL injection payload: Construct boolean-based or time-based blind SQL injection payloads (e.g., using AND SLEEP(5)-- or conditional expressions) to infer database structure without direct output.
  4. Enumerate database: Use automated tools such as sqlmap with the identified endpoint and parameter to enumerate database names, tables, and columns (e.g., sqlmap -u "https://target.com/wp-admin/admin-ajax.php?action=lumise_..." --level=3 --risk=2 --blind).
  5. Extract sensitive data: Dump target tables such as wp_users to retrieve hashed passwords, email addresses, and other sensitive information for offline cracking or further exploitation (Feedly).

Indicators of compromise

  • Network: Unusual or repeated HTTP requests to Lumise Product Designer plugin endpoints (e.g., wp-admin/admin-ajax.php with Lumise-specific action parameters) containing SQL metacharacters (', --, AND, SLEEP, BENCHMARK, OR 1=1).
  • Logs: WordPress or web server access logs showing high volumes of requests to plugin-specific endpoints with encoded or obfuscated query strings; time-delayed responses suggesting time-based blind injection (e.g., responses taking 5+ seconds).
  • Database: Unexpected or anomalous database query patterns in MySQL slow query logs, particularly queries with SLEEP() or BENCHMARK() functions originating from the web application user.
  • Process: Unusual database load spikes correlating with web requests to the Lumise plugin endpoints (Feedly).

Mitigation and workarounds

The vendor (King-Theme) has released a patched version: Lumise Product Designer 2.0.9. All users should immediately upgrade to version 2.0.9 or later via the WordPress plugin dashboard. For installations that cannot be updated immediately, implement web application firewall (WAF) rules to block SQL injection patterns targeting the plugin's endpoints, and restrict access to plugin components at the network level. Monitor application and database logs for suspicious SQL injection patterns as an interim detection measure (Feedly, Patchstack).

Community reactions

The vulnerability was reported and coordinated by Patchstack, a WordPress security platform, and was included in the Wordfence Intelligence Weekly WordPress Vulnerability Report for the week of March 16–22, 2026. No significant independent researcher commentary or broader media coverage has been identified beyond standard vulnerability database listings (Wordfence).

Additional resources


Source: This report was generated using AI

Related WordPress vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-86850MEDIUM6.5
  • sku-error-fixer-for-woocommerce
NoNoOct 06, 2026
CVE-2026-88931MEDIUM5.3
  • social-web-suite
NoNoOct 06, 2026
CVE-2026-87841MEDIUM5.3
  • unitechpay-paiements-mobile-money
NoNoOct 06, 2026
CVE-2026-92990MEDIUM5.3
  • sendpress
NoNoOct 06, 2026
CVE-2026-92989MEDIUM4.3
  • sendpress
NoNoOct 06, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management