CVE-2025-68056

8.5

LambertGroup LBG · Zoominoutslider

The LBG Zoominoutslider WordPress plugin is vulnerable to SQL injection, allowing authenticated attackers to execute unauthorized database queries.

Executive summary

A high-severity SQL injection vulnerability in the LambertGroup LBG Zoominoutslider plugin permits authenticated attackers to compromise backend database integrity.

Vulnerability

The plugin fails to properly neutralize special elements used in SQL commands, resulting in an SQL Injection (CWE-89) vulnerability. Based on the CVSS vector (PR:L), this flaw requires the attacker to have at least low-level authenticated access to the WordPress environment to trigger the malicious payload.

Business impact

Successful exploitation of this vulnerability allows an attacker to manipulate backend database queries, potentially leading to unauthorized data exfiltration or partial system disruption. With a CVSS score of 8.5, this high-severity flaw poses a significant risk to the confidentiality and availability of the WordPress site. The potential for unauthorized database interaction could lead to the compromise of sensitive site information or administrative credentials stored within the database.

Remediation

Immediate Action: Update the LambertGroup LBG Zoominoutslider plugin to version 5.4.5 or the latest available release to resolve the SQL injection flaw.

Proactive Monitoring: Review database query logs for unusual syntax or patterns that deviate from standard plugin operations.

Compensating Controls: Implement a Web Application Firewall (WAF) with updated rulesets designed to detect and block common SQL injection patterns targeting WordPress plugins.

Exploitation status

Public Exploit Available: No — there is no confirmed public exploit in the available data.

Analyst recommendation

Given the high CVSS score and the direct threat to database integrity, administrators should prioritize updating the Zoominoutslider plugin to the latest version immediately. Organizations unable to patch should restrict access to the affected plugin settings or disable the component until a secure version is deployed to mitigate the risk of unauthorized database interaction.

More LambertGroup LBG CVEs

Sources

Originally found and disclosed by João Pedro S Alcântara (Kinorth) | Patchstack Bug Bounty Program, per the CVE Program record.