
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2025-49049 is a SQL Injection vulnerability in the ZoomIt DZS Video Gallery WordPress plugin (dzs-videogallery), classified under CWE-89. It affects all versions of the plugin through 12.39, with version 12.40 being the first patched release. The vulnerability was reported by researcher João Pedro S Alcântara (Kinorth) on August 30, 2025, and publicly disclosed by Patchstack on January 12–22, 2026. It carries a CVSS v3.1 base score of 8.5 (High), assigned by Patchstack (Patchstack).
The vulnerability is rooted in improper neutralization of user-supplied input in SQL queries (CWE-89), meaning the plugin fails to sanitize or use parameterized queries when constructing database commands. An authenticated attacker with low privileges (Subscriber-level) can inject malicious SQL syntax over the network without any user interaction. The changed scope (S:C) in the CVSS vector indicates the impact can extend beyond the vulnerable plugin component itself, potentially affecting the broader WordPress database. The vulnerability was discovered and reported through Patchstack's responsible disclosure program (Patchstack).
Successful exploitation allows an authenticated attacker to execute arbitrary SQL commands against the WordPress database, resulting in high confidentiality impact — including unauthorized access to sensitive data such as user credentials, private content, and plugin-stored information. Availability is also marginally affected (LOW), with potential for service disruption. Because the scope is changed, the impact can extend beyond the DZS Video Gallery plugin to other data within the shared database environment, increasing the risk of broader site compromise (Patchstack).
There is no public proof-of-concept exploit code known at this time, and no evidence of active in-the-wild exploitation has been reported. The EPSS score is approximately 0.021%, indicating a low current probability of exploitation. The vulnerability requires at minimum Subscriber-level authentication, which slightly raises the exploitation bar compared to unauthenticated flaws. No threat actor attribution or CISA KEV catalog listing has been identified for this CVE (Patchstack).
The primary remediation is to update the DZS Video Gallery plugin to version 12.40 or later, which contains the fix for this SQL injection vulnerability. Patchstack has also issued a virtual patching/mitigation rule for its subscribers that blocks both legitimate and illegitimate requests exploiting this vulnerability until an update can be applied. As additional hardening measures, administrators should restrict database user privileges to the minimum required, implement a Web Application Firewall (WAF) with SQL injection detection rules, and monitor database activity for anomalous queries (Patchstack).
Wordfence included this vulnerability in its weekly WordPress vulnerability intelligence report for the week of January 12–18, 2026, highlighting it as part of broader plugin security tracking. No significant independent researcher commentary or major media coverage beyond standard vulnerability database reporting has been identified for this CVE.
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."