Extension WordPress

Vulnérabilités All-in-One Video Gallery

Cette page rassemble les failles publiées pour All-in-One Video Gallery, leurs plages de versions affectées et les correctifs signalés dans la base locale.

14Vulnérabilités
0Critiques
14Avec correctif
8,8CVSS maximal

Historique de sécurité

CVE et vulnérabilités de All-in-One Video Gallery

14 fiches

CVE-2026-12123 Moyenne · 6,4
All-in-One Video Gallery

All-in-One Video Gallery <= 4.8.5 – Authenticated (Subscriber+) Server-Side Request Forgery via 'vdl' Parameter

The All-in-One Video Gallery plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 4.8.5 via the 'vdl' parameter. This makes it possible for authenticated attackers, with subscriber-level access and above, to…

Versions affectées

*-4.8.5

Correctif

4.9.0

Publication

09/07/2026

CVE-2025-15516 Moyenne · 4,3
All-in-One Video Gallery

All-in-One Video Gallery 4.1.0 – 4.6.4 – Missing Authorization to Authenticated (Subscriber+) Limited User Meta Update

The All-in-One Video Gallery plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the ajax_callback_store_user_meta() function in versions 4.1.0 to 4.6.4. This makes it possible for authenticated attackers, with Subscriber-level…

Versions affectées

4.1.0-4.6.4

Correctif

4.7.1

Publication

23/01/2026

CVE-2025-14947 Moyenne · 6,5
All-in-One Video Gallery

All-in-One Video Gallery <= 4.6.4 – Missing Authorization to Unauthenticated Bunny Stream Video Creation/Deletion

The All-in-One Video Gallery plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the `ajax_callback_create_bunny_stream_video`, `ajax_callback_get_bunny_stream_video`, and `ajax_callback_delete_bunny_stream_video` functions in all versions up to, and including, 4.6.4. This makes it…

Versions affectées

*-4.6.4

Correctif

4.7.1

Publication

22/01/2026

CVE-2025-12957 Élevée · 8,8
All-in-One Video Gallery

All-in-One Video Gallery <= 4.5.7 – Authenticated (Author+) Arbitrary File Upload via VTT Upload Bypass

The All-in-One Video Gallery plugin for WordPress is vulnerable to arbitrary file upload in all versions up to, and including, 4.5.7. This is due to insufficient file type validation detecting VTT files, allowing double extension files to bypass…

Versions affectées

*-4.5.7

Correctif

4.6.4

Publication

15/01/2026

CVE-2025-12966 Élevée · 8,8
All-in-One Video Gallery

All-in-One Video Gallery 4.5.4 – 4.5.7 – Authenticated (Author+) Arbitrary File Upload via Import ZIP

The All-in-One Video Gallery plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the resolve_import_directory() function in versions 4.5.4 to 4.5.7. This makes it possible for authenticated attackers, with Author-level access…

Versions affectées

4.5.4-4.5.7

Correctif

4.6.4

Publication

05/12/2025

CVE-2024-6629 Moyenne · 6,4
All-in-One Video Gallery

All-in-One Video Gallery <= 3.7.1 – Authenticated (Contributor+) Stored Cross-Site Scripting via Video Shortcode

The All-in-One Video Gallery plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Video shortcode in all versions up to, and including, 3.7.1 due to insufficient input sanitization and output escaping on user supplied attributes.…

Versions affectées

*-3.7.1

Correctif

3.8.3

Publication

23/07/2024

CVE-2024-4670 Élevée · 8,8
All-in-One Video Gallery

All-in-One Video Gallery <= 3.6.5 – Authenticated (Contributor+) Local File Inclusion via aiovg_search_form Shortcode

The All-in-One Video Gallery plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 3.6.5 via the aiovg_search_form shortcode. This makes it possible for authenticated attackers, with contributor-level access and above, to…

Versions affectées

*-3.6.5

Correctif

3.7.0

Publication

14/05/2024

CVE-2024-4033 Élevée · 8,8
All-in-One Video Gallery

All-in-One Video Gallery <= 3.6.4 – Authenticated (Contributor+) Arbitrary File Upload via featured image

The All-in-One Video Gallery plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the aiovg_create_attachment_from_external_image_url function in all versions up to, and including, 3.6.4. This makes it possible for authenticated attackers,…

Versions affectées

*-3.6.4

Correctif

3.6.5

Publication

01/05/2024

CVE-2023-33999 Moyenne · 6,1
All-in-One Video Gallery

Freemius SDK <= 2.5.9 – Reflected Cross-Site Scripting via fs_request_get

The Freemius SDK for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘fs_request_get’ function in versions up to, and including, 2.5.9 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to…

Versions affectées

1.5.7-3.3.0

Correctif

3.4.3

Publication

18/07/2023

CVE-2022-2633 Élevée · 7,5
All-in-One Video Gallery

All-in-One Video Gallery 2.5.8 – 2.6.0 – Arbitrary File Download & Server-Side Request Forgery

The All-in-One Video Gallery plugin for WordPress is vulnerable to arbitrary file downloads and blind server-side request forgery via the 'dl' parameter found in the ~/public/video.php file in versions up to, and including 2.6.0. This makes it possible…

Versions affectées

2.5.8-2.6.0

Correctif

2.6.1

Publication

17/08/2022

WP Commander

Rechercher dans toute la base WordPress

Utilisez la recherche globale pour retrouver une extension, un thème, une CVE ou un identifiant de vulnérabilité.

Ouvrir le tableau des vulnérabilités