QID 730628
Date Published: 2022-10-31
QID 730628: WordPress Plugin All In One Video Gallery Blind Server-Side Request Forgery (SSRF) Vulnerability
All-in-One Video Gallery is a video posts plugin that helps you add videos as posts and build scalable, searchable, SEO-optimized video galleries in minutes.
The All-in-One Video Gallery plugin for WordPress is vulnerable to arbitrary file downloads and blind server-side request forgery via the 'dl' parameter found in the ~/public/video.php file in versions up to, and including 2.6.0
Affected Versions:
All-In-One Video Gallery versions prior to 2.6.1
QID Detection Logic(Unauthenticated): This unauthenticated detection depends on the BlindElephant engine to detect the vulnerable version of the All-In-one Video Gallery plugin.
Successful exploitation of this vulnerability may allow an attacker to download arbitrary file from the affected system.
- All In One Video Gallery Release Notes -
wordpress.org/plugins/all-in-one-video-gallery/#developers
CVEs related to QID 730628
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| All In One Video Gallery Release Notes |
|