SQL Injection Vulnerability in Multimedia Responsive Carousel by LambertGroup
CVE-2025-31928
8.5HIGH
Key Information:
- Vendor
WordPress
- Vendor
- CVE Published:
- 16 May 2025
What is CVE-2025-31928?
An SQL Injection vulnerability exists in the Multimedia Responsive Carousel that allows attackers to manipulate SQL queries through specially crafted input. This can lead to unauthorized access to sensitive data or compromise the integrity of the database. The affected version is prior to 2.6.0, which fails to properly neutralize special elements in SQL commands, leaving systems exposed to potential database exploitation. It is crucial for users of the affected product to upgrade to the latest version to safeguard against this vulnerability.
Affected Version(s)
Multimedia Responsive Carousel with Image Video Audio Support <= 2.6.0
References
CVSS V3.1
Score:
8.5
Severity:
HIGH
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Changed
Timeline
Vulnerability published
Vulnerability Reserved
Credit
Tran Nguyen Bao Khanh (VCI - VNPT Cyber Immunity) (Patchstack Alliance)