Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in LambertGroup Image&Video FullScreen Background l...
Description
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in LambertGroup Image&Video FullScreen Background lbg_fullscreen_fullwidth_slider allows SQL Injection
AI Analyst Comment
Remediation
Apply vendor patches immediately. Review database access controls and enable query logging.
---METADATA---
VENDOR: LambertGroup
PRODUCT: Image&Video FullScreen Background
AFFECTED_VERSIONS: 0 through 1.6.7
CONFIDENCE: high
MISSING: patch
CREDITS: João Pedro S Alcântara (Kinorth) | Patchstack Bug Bounty Program (finder)
SOURCES_JSON: [{"url":"https://patchstack.com/database/Wordpress/Plugin/lbg_fullscreen_fullwidth_slider/vulnerability/wordpress-image-video-fullscreen-background-plugin-1-6-7-sql-injection-vulnerability?_s_id=cve","name":null,"tags":["vdb-entry"]}]
PROFILE: batch@eb21ac00f78b
MODEL: gemini-3.1-flash-lite
GENERATED: 2026-08-29T14:11:46.858Z
---END_METADATA---
Description Summary:
A SQL injection vulnerability in the Image&Video FullScreen Background WordPress plugin allows authenticated attackers to execute arbitrary SQL commands.
Executive Summary:
A critical SQL injection vulnerability in the LambertGroup Image&Video FullScreen Background plugin allows authenticated attackers to compromise database integrity and confidentiality.
Vulnerability Details
CVE-ID: CVE-2025-62093
Affected Software: LambertGroup Image&Video FullScreen Background
Affected Versions: 0 through 1.6.7
Vulnerability: This vulnerability involves improper neutralization of special elements used in SQL commands within the lbg_fullscreen_fullwidth_slider component. The CVSS vector indicates that this flaw is accessible to authenticated users with low privileges.
Business Impact
Successful exploitation of this SQL injection vulnerability could lead to unauthorized access to sensitive database information. Given the CVSS score of 8.5, this high-severity flaw poses a significant risk to data confidentiality and potentially system availability, which may result in severe reputational damage and regulatory non-compliance.
Remediation Plan
Immediate Action: Since a specific patch is not currently confirmed, administrators should immediately deactivate or uninstall the Image&Video FullScreen Background plugin until a secure version is released by the vendor.
Proactive Monitoring: Security teams should review database query logs for anomalous patterns or unauthorized access attempts originating from the plugin's associated endpoints.
Compensating Controls: Deploy a Web Application Firewall (WAF) with rules configured to detect and block common SQL injection payloads targeting WordPress plugins.
Exploitation Status
Public Exploit Available: Unknown.
Analyst Notes: As of December 10, 2025, there is no public information indicating active exploitation or a public proof-of-concept for this vulnerability. SQL injection remains a high-risk vector that should be addressed promptly through defensive configuration and software lifecycle management.
Analyst Recommendation
The severity of this vulnerability necessitates immediate action to protect the underlying database environment. Administrators must prioritize the deactivation of the affected plugin until the vendor provides a verified security update, as this remains the most effective method to mitigate the risk of unauthorized data exposure.