VendorsPlugins360all-in-one_video_galleryall versions
Vulnerabilities

Plugins360 All-in-One Video Gallery

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

4CVEs
CVE-2024-31248
WordPress All-in-One Video Gallery plugin <= 3.5.2 - Broken Access Control vulnerability
Published 2024-06-09 · Analyzed
8.8EPSS 0.004
CVE-2022-2633
The All-in-One Video Gallery plugin for WordPress is vulnerable to arbitrary file downloads and blind server-side request forgery via the 'dl' parameter found in the ~/public/video.php file in versions up to, and including 2.6.0. This makes it possible for unauthenticated users to download sensitive files hosted on the affected server and forge requests to the server.
Published 2022-09-06 · Modified
8.2EPSS 0.338
CVE-2021-24970
All-In-One-Gallery < 2.5.0 - Admin+ Local File Inclusion
Published 2021-12-13 · Modified
7.2EPSS 0.059
CVE-2024-6629
All-in-One Video Gallery <= 3.7.1 - Authenticated (Contributor+) Stored Cross-Site Scripting via Video Shortcode
Published 2024-07-24 · Modified
6.4EPSS 0.003