All-in-One Video Gallery <= 4.9.5 - Unauthenticated Pricing Page Configuration Injection

Medium 4.3 CWE-915Fixed in 4.9.7
ID
WPSEC-2026-0759
Plugin
All-in-One Video Gallery – Video Player & Galleries for YouTube, Vimeo & Self-Hosted Videos (all-in-one-video-gallery)
Affected
all versions before 4.9.7
Remediation
Update to 4.9.7 or later.
CVSS 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N
Weakness
CWE-915
Usage
Plugin Medium · Affected versions Low among sites WPSec scans, 2026-10-11
Attack surface
All-in-One Video Gallery on WPSec AttackSurface
Fix released
Published

Description

The All-in-One Video Gallery plugin for WordPress is vulnerable to configuration injection via the pricing page of the bundled Freemius SDK in all versions up to, and including, 4.9.5. This is due to the pricing app configuration being built by merging request query parameters over trusted values such as plugin_id, mode, fs_wp_endpoint_url and request_handler_url before they are passed to the inline pricing script. This makes it possible for unauthenticated attackers to point the pricing page's requests and checkout redirects at attacker-controlled URLs if they can trick a site administrator into opening a crafted link and acting on the page.

References

Published by WPSec. Provided as is, without warranty. Corrections: contact us.

This advisory as JSON or Markdown · All advisories: JSON, RSS

License: CC BY 4.0