VYPR
High severity8.5NVD Advisory· Published Dec 9, 2025· Updated Apr 27, 2026

CVE-2025-62093

CVE-2025-62093

Description

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in LambertGroup Image&Video FullScreen Background lbg_fullscreen_fullwidth_slider allows SQL Injection.This issue affects Image&Video FullScreen Background: from n/a through <= 1.6.7.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

SQL injection in LambertGroup Image&Video FullScreen Background plugin (≤1.6.7) allows unauthenticated attackers to execute arbitrary SQL commands.

Vulnerability

Overview

The LambertGroup Image&Video FullScreen Background plugin for WordPress (versions up to and including 1.6.7) contains a SQL injection vulnerability due to improper neutralization of special elements used in an SQL command. This flaw exists in the lbg_fullscreen_fullwidth_slider component, where user-supplied input is not properly sanitized before being used in database queries [1].

Exploitation

An attacker can exploit this vulnerability without requiring authentication, making it accessible to any remote user. The attack vector is network-based, and the low complexity of exploitation means that automated tools can easily target vulnerable installations. This type of vulnerability is frequently used in mass-exploit campaigns against WordPress sites, regardless of their size or popularity [1].

Impact

Successful exploitation allows an attacker to directly interacting with the underlying database, which could lead to data theft, modification, deletion, or exfiltration. An attacker could potentially steal sensitive information such as user credentials, personal data, or other stored content, or other database records. The CVSS v3 score of 8.5 (High) reflects the significant confidentiality and integrity impact [1].

Mitigation

Users are strongly advised to update the plugin to a patched version 1.6.8 or later as soon as possible. If an immediate update is not feasible, site owners should contact their hosting provider or a web developer for assistance. No workarounds have been published, and the vendor has not indicated that older versions will receive a patch [1].

AI Insight generated on May 19, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.

Affected products

2

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

1

News mentions

0

No linked articles in our index yet.