CVE-2025-62093
8.5LambertGroup · Image&Video FullScreen Background
A SQL injection vulnerability in the Image&Video FullScreen Background WordPress plugin allows authenticated attackers to execute arbitrary SQL commands.
Executive summary
A critical SQL injection vulnerability in the LambertGroup Image&Video FullScreen Background plugin allows authenticated attackers to compromise database integrity and confidentiality.
Vulnerability
This vulnerability involves improper neutralization of special elements used in SQL commands within the lbg_fullscreen_fullwidth_slider component. The CVSS vector indicates that this flaw is accessible to authenticated users with low privileges.
Business impact
Successful exploitation of this SQL injection vulnerability could lead to unauthorized access to sensitive database information. Given the CVSS score of 8.5, this high-severity flaw poses a significant risk to data confidentiality and potentially system availability, which may result in severe reputational damage and regulatory non-compliance.
Remediation
Immediate Action: Since a specific patch is not currently confirmed, administrators should immediately deactivate or uninstall the Image&Video FullScreen Background plugin until a secure version is released by the vendor.
Proactive Monitoring: Security teams should review database query logs for anomalous patterns or unauthorized access attempts originating from the plugin's associated endpoints.
Compensating Controls: Deploy a Web Application Firewall (WAF) with rules configured to detect and block common SQL injection payloads targeting WordPress plugins.
Exploitation status
Public Exploit Available: Unknown.
Analyst recommendation
The severity of this vulnerability necessitates immediate action to protect the underlying database environment. Administrators must prioritize the deactivation of the affected plugin until the vendor provides a verified security update, as this remains the most effective method to mitigate the risk of unauthorized data exposure.
More LambertGroup CVEs
Sources
Originally found and disclosed by João Pedro S Alcântara (Kinorth) | Patchstack Bug Bounty Program, per the CVE Program record.