🔐 CVE Alert

CVE-2025-49049

HIGH 8.8

WordPress DZS Video Gallery plugin <= 12.39 - SQL Injection vulnerability

CVSS Score
8.8
EPSS Score
0.0%
EPSS Percentile
0th

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in ZoomIt DZS Video Gallery dzs-videogallery allows SQL Injection.This issue affects DZS Video Gallery: from n/a through <= 12.39.

CWE CWE-89
Vendor zoomit
Product dzs video gallery
Published Jan 22, 2026
Last Updated Apr 1, 2026
Stay Ahead of the Next One

Get instant alerts for zoomit dzs video gallery

Be the first to know when new high vulnerabilities affecting zoomit dzs video gallery are published — delivered to Slack, Telegram or Discord.

Get Free Alerts → Free · No credit card · 60 sec setup

Affected Versions

ZoomIt / DZS Video Gallery
0 ≤ 12.39

References

NVD ↗ CVE.org ↗ EPSS Data ↗
patchstack.com: https://patchstack.com/database/Wordpress/Plugin/dzs-videogallery/vulnerability/wordpress-dzs-video-gallery-plugin-12-37-sql-injection-vulnerability?_s_id=cve

Credits

João Pedro S Alcântara (Kinorth) | Patchstack Bug Bounty Program