← WordPress Vulnerabilities
WordPress security by component

All-in-One Video Gallery

All-in-One Video Gallery is a WordPress component with 12 published CVE records in this archive. The latest tracked vulnerability was published Jul 10, 2026; the highest CVE/CNA score is 8.8.

Plugin slug: all-in-one-video-gallery

CVE-2026-12123: All-in-One Video Gallery: Server-side request forgery

All-in-One Video Gallery is affected by server-side request forgery. The vulnerable path is reachable without authentication. The vulnerable server can be induced to make attacker-selected network requests. The published affected range is <= 4.8.5.

PublishedJul 10, 2026
Known safe version> 4.8.5
Safe version
Jul 10, 2026 CVE-2026-12123
All-in-One Video Gallery: Server-side request forgery
All-in-One Video Gallery is affected by server-side request forgery. The vulnerable path is reachable without authentication. The vulnerable server can be induced to make attacker-selected network requests. The published affected range is <= 4.8.5.
> 4.8.5
CVE6.4
NVDPending
Mar 04, 2026 CVE-2026-1706
All-in-One Video Gallery: Cross-site scripting
All-in-One Video Gallery is affected by cross-site scripting. The vulnerable path is reachable without authentication. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE6.1
NVDPending
Jan 24, 2026 CVE-2025-15516
All-in-One Video Gallery: A security weakness
All-in-One Video Gallery is affected by a security weakness. Exploitation requires at least subscriber-level access. The resulting impact depends on how the affected component exposes the vulnerable operation.
See mitigation notes
CVE4.3
NVDPending
Jan 23, 2026 CVE-2025-14947
All-in-One Video Gallery: A security weakness
All-in-One Video Gallery is affected by a security weakness. The vulnerable path is reachable without authentication. The resulting impact depends on how the affected component exposes the vulnerable operation.
See mitigation notes
CVE6.5
NVDPending
Jan 16, 2026 CVE-2025-12957
All-in-One Video Gallery: Dangerous file upload
All-in-One Video Gallery is affected by dangerous file upload. Exploitation requires at least author-level access. Successful exploitation can place attacker-controlled executable content on the server and may lead to full site compromise.
See mitigation notes
CVE8.8
NVDPending
Dec 06, 2025 CVE-2025-12966
All-in-One Video Gallery: Dangerous file upload
All-in-One Video Gallery is affected by dangerous file upload. Exploitation requires at least author-level access. Successful exploitation can place attacker-controlled executable content on the server and may lead to full site compromise.
See mitigation notes
CVE8.8
NVDPending
Jul 24, 2024 CVE-2024-6629
All-in-One Video Gallery: Cross-site scripting
All-in-One Video Gallery is affected by cross-site scripting. Exploitation requires at least contributor-level access. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE6.4
NVD5.4
Jun 09, 2024 CVE-2024-31248
All-in-One Video Gallery: A security weakness
All-in-One Video Gallery is affected by a security weakness. Exposure depends on how the affected operation is made reachable by the site. The resulting impact depends on how the affected component exposes the vulnerable operation.
See mitigation notes
CVE4.3
NVD8.8
May 15, 2024 CVE-2024-4670
All-in-One Video Gallery: Filesystem traversal
All-in-One Video Gallery is affected by filesystem traversal. Exploitation requires at least contributor-level access. A crafted path can escape the intended directory and reach files or directories elsewhere on the server.
See mitigation notes
CVE8.8
NVDPending
May 02, 2024 CVE-2024-4033
All-in-One Video Gallery: Dangerous file upload
All-in-One Video Gallery is affected by dangerous file upload. Exploitation requires an authenticated WordPress account. Successful exploitation can place attacker-controlled executable content on the server and may lead to full site compromise.
See mitigation notes
CVE8.8
NVDPending
Sep 06, 2022 CVE-2022-2633
All-in-One Video Gallery: Server-side request forgery
All-in-One Video Gallery is affected by server-side request forgery. The vulnerable path is reachable without authentication. The vulnerable server can be induced to make attacker-selected network requests.
See mitigation notes
CVE7.5
NVD8.2
Dec 13, 2021 CVE-2021-24970
All-in-One Video Gallery: Filesystem traversal
All-in-One Video Gallery is affected by filesystem traversal. Exposure depends on how the affected operation is made reachable by the site. A crafted path can escape the intended directory and reach files or directories elsewhere on the server.
See mitigation notes
CVE7.2
NVD7.2