{
 "id": "WPSEC-2026-0759",
 "url": "https://wpsec.com/vuln/WPSEC-2026-0759/",
 "json_url": "https://wpsec.com/vuln/WPSEC-2026-0759/advisory.json",
 "markdown_url": "https://wpsec.com/vuln/WPSEC-2026-0759/index.md",
 "title": "All-in-One Video Gallery <= 4.9.5 - Unauthenticated Pricing Page Configuration Injection",
 "description": "The All-in-One Video Gallery plugin for WordPress is vulnerable to configuration injection via the pricing page of the bundled Freemius SDK in all versions up to, and including, 4.9.5. This is due to the pricing app configuration being built by merging request query parameters over trusted values such as plugin_id, mode, fs_wp_endpoint_url and request_handler_url before they are passed to the inline pricing script. This makes it possible for unauthenticated attackers to point the pricing page's requests and checkout redirects at attacker-controlled URLs if they can trick a site administrator into opening a crafted link and acting on the page.",
 "plugin": {
  "slug": "all-in-one-video-gallery",
  "name": "All-in-One Video Gallery",
  "full_name": "All-in-One Video Gallery – Video Player & Galleries for YouTube, Vimeo & Self-Hosted Videos",
  "wordpress_org": "https://wordpress.org/plugins/all-in-one-video-gallery/",
  "advisories_url": "https://wpsec.com/vuln/plugin/all-in-one-video-gallery/",
  "attacksurface": "https://attacksurface.wpsec.com/plugin/all-in-one-video-gallery"
 },
 "type": "CONTENT INJECTION",
 "cwe": [
  "CWE-915"
 ],
 "cve": [],
 "cvss": {
  "version": "3.1",
  "score": 4.3,
  "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N",
  "severity": "Medium"
 },
 "affected": {
  "ranges": [
   {
    "from": null,
    "from_inclusive": true,
    "to": "4.9.7",
    "to_inclusive": false
   }
  ],
  "text": [
   "all versions before 4.9.7"
  ]
 },
 "introduced_in": null,
 "fixed_in": "4.9.7",
 "remediation": "Update to 4.9.7 or later.",
 "fix_released": "2026-10-10T08:03:01+00:00",
 "published": "2026-10-11T08:41:09+00:00",
 "updated": "2026-10-10T14:53:10.316095+00:00",
 "also_published_as": null,
 "references": [
  "https://wpsec.com/vuln/WPSEC-2026-0759/",
  "https://plugins.svn.wordpress.org/all-in-one-video-gallery/tags/4.9.7/",
  "https://wordpress.org/plugins/all-in-one-video-gallery/"
 ],
 "attacksurface_url": "https://attacksurface.wpsec.com/plugin/all-in-one-video-gallery",
 "source": "WPSec",
 "license": {
  "name": "CC BY 4.0",
  "url": "https://creativecommons.org/licenses/by/4.0/"
 },
 "usage": {
  "plugin": "Medium",
  "affected_versions": "Low",
  "as_of": "2026-10-11"
 }
}