SQL Injection Vulnerability in Multimedia Responsive Carousel by LambertGroup
CVE-2025-31928
Key Information:
- Vendor
WordPress
- Vendor
- CVE Published:
- 16 May 2025
What is CVE-2025-31928?
An SQL Injection vulnerability exists in the Multimedia Responsive Carousel that allows attackers to manipulate SQL queries through specially crafted input. This can lead to unauthorized access to sensitive data or compromise the integrity of the database. The affected version is prior to 2.6.0, which fails to properly neutralize special elements in SQL commands, leaving systems exposed to potential database exploitation. It is crucial for users of the affected product to upgrade to the latest version to safeguard against this vulnerability.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
Multimedia Responsive Carousel with Image Video Audio Support <= 2.6.0
References
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved