Impact
The DZS Video Gallery plugin for WordPress contains an Improper Neutralization of Special Elements used in an SQL command (CWE-89), allowing attackers to inject arbitrary SQL statements into database queries. Because the plugin accepts unsanitized input and concatenates it directly into SQL commands, a successful injection could grant read or write access to the WordPress database, exposing sensitive content or creating privileged accounts.
Affected Systems
All installations of the ZoomIt DZS Video Gallery plugin for WordPress with a version of 12.39 or earlier are affected. The vulnerability exists regardless of the underlying WordPress core version and does not depend on any additional plugins. Administrators should verify the plugin version on every site that uses this component.
Risk and Exploitability
The CVSS score of 8.5 indicates high severity, while the EPSS score of less than 1% suggests low current exploitation activity and no listing in the CISA KEV catalog. The description implies that the flaw can be triggered by external users sending crafted requests to the plugin’s exposed input fields or endpoints; this inference is based on the reported lack of input sanitization and the typical exposure of plugin parameters. Consequently, live websites that rely on this plugin without additional filtering remain at elevated risk. Immediate remediation through an upgrade is recommended to eliminate the flaw and reduce the attack surface.
OpenCVE Enrichment