VYPR
High severity8.5NVD Advisory· Published Dec 16, 2025· Updated Apr 27, 2026

CVE-2025-68054

CVE-2025-68054

Description

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in LambertGroup CountDown With Image or Video Background countdown_with_background allows Blind SQL Injection.This issue affects CountDown With Image or Video Background: from n/a through <= 1.5.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Blind SQL injection in WordPress CountDown With Image or Video Background plugin up to 1.5 allows database interaction.

The CountDown With Image or Video Background plugin for WordPress versions through 1.5 contains a blind SQL injection vulnerability due to improper neutralization of special elements used in an SQL command. This flaw exists in the countdown_with_background component, allowing an attacker to inject arbitrary SQL queries.

Exploitation does not require authentication and can be performed over the network. The blind nature of the injection means an attacker can infer information from the database by observing differences in application responses. This attack vector is commonly used in mass-exploit campaigns targeting WordPress sites [1].

Successful exploitation could allow an attacker to retrieve sensitive data from the database, such as user credentials or other confidential information. The CVSS score of 8.5 (High) reflects the potential for significant impact on confidentiality [1].

The vulnerability affects all versions up to and including 1.5. Users are strongly advised to update the plugin to a patched version as soon as possible. If immediate updating is not feasible, temporary measures such as disabling the plugin or consulting with a web hosting provider are recommended [1].

AI Insight generated on May 19, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.

Affected products

1

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

1

News mentions

0

No linked articles in our index yet.