VYPR

All In One Video Gallery

by WordPress

Source repositories

CVEs (13)

  • CVE-2024-4033HigMay 2, 2024
    risk 0.57cvss 8.8epss 0.02

    The All-in-One Video Gallery plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the aiovg_create_attachment_from_external_image_url function in all versions up to, and including, 3.6.4. This makes it possible for authenticated…

  • CVE-2022-2633HigSep 6, 2022
    risk 0.51cvss 7.5epss 0.27

    The All-in-One Video Gallery plugin for WordPress is vulnerable to arbitrary file downloads and blind server-side request forgery via the 'dl' parameter found in the ~/public/video.php file in versions up to, and including 2.6.0. This makes it possible for unauthenticated users…

  • CVE-2025-12957HigJan 16, 2026
    risk 0.50cvss 8.8epss 0.01

    The All-in-One Video Gallery plugin for WordPress is vulnerable to arbitrary file upload in all versions up to, and including, 4.5.7. This is due to insufficient file type validation detecting VTT files, allowing double extension files to bypass sanitization while being accepted…

  • CVE-2025-12966HigDec 6, 2025
    risk 0.50cvss 8.8epss 0.01

    The All-in-One Video Gallery plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the resolve_import_directory() function in versions 4.5.4 to 4.5.7. This makes it possible for authenticated attackers, with Author-level access and…

  • CVE-2024-4670HigMay 15, 2024
    risk 0.50cvss 8.8epss 0.01

    The All-in-One Video Gallery plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 3.6.5 via the aiovg_search_form shortcode. This makes it possible for authenticated attackers, with contributor-level access and above, to include and…

  • CVE-2021-24970HigDec 13, 2021
    risk 0.47cvss 7.2epss 0.06

    The All-in-One Video Gallery WordPress plugin before 2.5.0 does not sanitise and validate the tab parameter before using it in a require statement in the admin dashboard, leading to a Local File Inclusion issue

  • CVE-2026-12123MedJul 10, 2026
    risk 0.35cvss 6.4epss 0.00

    The All-in-One Video Gallery plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 4.8.5 via the 'vdl' parameter. This makes it possible for authenticated attackers, with subscriber-level access and above, to make web requests to…

  • CVE-2025-14947MedJan 23, 2026
    risk 0.35cvss 6.5epss 0.00

    The All-in-One Video Gallery plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the `ajax_callback_create_bunny_stream_video`, `ajax_callback_get_bunny_stream_video`, and `ajax_callback_delete_bunny_stream_video`…

  • CVE-2024-6629MedJul 24, 2024
    risk 0.35cvss 6.4epss 0.00

    The All-in-One Video Gallery plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Video shortcode in all versions up to, and including, 3.7.1 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it…

  • CVE-2026-19075MedAug 10, 2026
    risk 0.33cvss 5.0epss 0.00

    All-in-One Video Gallery registers a public, unauthenticated file-download handler triggered by `?vdl=<post_id>` on any `aiovg_videos` post (`public/video.php`, `AIOVG_Public_Video::download_video()`), which reads the post's `mp4` meta value and streams that URL's response back…

  • CVE-2026-1706MedMar 4, 2026
    risk 0.33cvss 6.1epss 0.00

    The All-in-One Video Gallery plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'vi' parameter in all versions up to, and including, 4.7.1 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers…

  • CVE-2025-15516MedJan 24, 2026
    risk 0.28cvss 4.3epss 0.00

    The All-in-One Video Gallery plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the ajax_callback_store_user_meta() function in versions 4.1.0 to 4.6.4. This makes it possible for authenticated attackers, with…

  • CVE-2024-31248MedJun 9, 2024
    risk 0.28cvss 4.3epss 0.00

    Missing Authorization vulnerability in Team Plugins360 All-in-One Video Gallery.This issue affects All-in-One Video Gallery: from n/a through 3.5.2.