CVE-2025-49049: 
WordPress vulnerability analysis and mitigation

Overview

CVE-2025-49049 is a SQL Injection vulnerability in the ZoomIt DZS Video Gallery WordPress plugin (dzs-videogallery), classified under CWE-89. It affects all versions of the plugin through 12.39, with version 12.40 being the first patched release. The vulnerability was reported by researcher João Pedro S Alcântara (Kinorth) on August 30, 2025, and publicly disclosed by Patchstack on January 12–22, 2026. It carries a CVSS v3.1 base score of 8.5 (High), assigned by Patchstack (Patchstack).

Technical details

The vulnerability is rooted in improper neutralization of user-supplied input in SQL queries (CWE-89), meaning the plugin fails to sanitize or use parameterized queries when constructing database commands. An authenticated attacker with low privileges (Subscriber-level) can inject malicious SQL syntax over the network without any user interaction. The changed scope (S:C) in the CVSS vector indicates the impact can extend beyond the vulnerable plugin component itself, potentially affecting the broader WordPress database. The vulnerability was discovered and reported through Patchstack's responsible disclosure program (Patchstack).

Impact

Successful exploitation allows an authenticated attacker to execute arbitrary SQL commands against the WordPress database, resulting in high confidentiality impact — including unauthorized access to sensitive data such as user credentials, private content, and plugin-stored information. Availability is also marginally affected (LOW), with potential for service disruption. Because the scope is changed, the impact can extend beyond the DZS Video Gallery plugin to other data within the shared database environment, increasing the risk of broader site compromise (Patchstack).

Exploitability

There is no public proof-of-concept exploit code known at this time, and no evidence of active in-the-wild exploitation has been reported. The EPSS score is approximately 0.021%, indicating a low current probability of exploitation. The vulnerability requires at minimum Subscriber-level authentication, which slightly raises the exploitation bar compared to unauthenticated flaws. No threat actor attribution or CISA KEV catalog listing has been identified for this CVE (Patchstack).

Mitigation and workarounds

The primary remediation is to update the DZS Video Gallery plugin to version 12.40 or later, which contains the fix for this SQL injection vulnerability. Patchstack has also issued a virtual patching/mitigation rule for its subscribers that blocks both legitimate and illegitimate requests exploiting this vulnerability until an update can be applied. As additional hardening measures, administrators should restrict database user privileges to the minimum required, implement a Web Application Firewall (WAF) with SQL injection detection rules, and monitor database activity for anomalous queries (Patchstack).

Community reactions

Wordfence included this vulnerability in its weekly WordPress vulnerability intelligence report for the week of January 12–18, 2026, highlighting it as part of broader plugin security tracking. No significant independent researcher commentary or major media coverage beyond standard vulnerability database reporting has been identified for this CVE.

Additional resources


Source: This report was generated using AI

Related WordPress vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-86850MEDIUM6.5
  • sku-error-fixer-for-woocommerce
NoNoOct 06, 2026
CVE-2026-88931MEDIUM5.3
  • social-web-suite
NoNoOct 06, 2026
CVE-2026-87841MEDIUM5.3
  • unitechpay-paiements-mobile-money
NoNoOct 06, 2026
CVE-2026-92990MEDIUM5.3
  • sendpress
NoNoOct 06, 2026
CVE-2026-92989MEDIUM4.3
  • sendpress
NoNoOct 06, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management