All-in-One Video Gallery <= 4.9.5 - Unauthenticated Pricing Page Configuration Injection
- ID
- WPSEC-2026-0759
- Plugin
- All-in-One Video Gallery – Video Player & Galleries for YouTube, Vimeo & Self-Hosted Videos (all-in-one-video-gallery)
- Affected
- all versions before 4.9.7
- Remediation
- Update to 4.9.7 or later.
- CVSS 3.1
- CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N
- Weakness
- CWE-915
- Usage
- Plugin Medium · Affected versions Low among sites WPSec scans, 2026-10-11
- Attack surface
- All-in-One Video Gallery on WPSec AttackSurface
- Fix released
- Published
Description
The All-in-One Video Gallery plugin for WordPress is vulnerable to configuration injection via the pricing page of the bundled Freemius SDK in all versions up to, and including, 4.9.5. This is due to the pricing app configuration being built by merging request query parameters over trusted values such as plugin_id, mode, fs_wp_endpoint_url and request_handler_url before they are passed to the inline pricing script. This makes it possible for unauthenticated attackers to point the pricing page's requests and checkout redirects at attacker-controlled URLs if they can trick a site administrator into opening a crafted link and acting on the page.
References
- https://wpsec.com/vuln/WPSEC-2026-0759/
- https://plugins.svn.wordpress.org/all-in-one-video-gallery/tags/4.9.7/
- https://wordpress.org/plugins/all-in-one-video-gallery/
Published by WPSec. Provided as is, without warranty. Corrections: contact us.
This advisory as JSON or Markdown · All advisories: JSON, RSS