# All-in-One Video Gallery <= 4.9.5 - Unauthenticated Pricing Page Configuration Injection

- **ID:** WPSEC-2026-0759
- **Plugin:** All-in-One Video Gallery – Video Player & Galleries for YouTube, Vimeo & Self-Hosted Videos (`all-in-one-video-gallery`), https://wordpress.org/plugins/all-in-one-video-gallery/
- **Affected versions:** all versions before 4.9.7
- **Fixed in:** 4.9.7 (Update to 4.9.7 or later.)
- **Severity:** Medium 4.3 (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N)
- **Weakness:** CWE-915
- **Usage among sites WPSec scans:** plugin Medium, affected versions Low (as of 2026-10-11)
- **Attack surface analysis:** https://attacksurface.wpsec.com/plugin/all-in-one-video-gallery
- **Fix released:** 2026-10-10
- **Published:** 2026-10-11
- **URL:** https://wpsec.com/vuln/WPSEC-2026-0759/

## Description

The All-in-One Video Gallery plugin for WordPress is vulnerable to configuration injection via the pricing page of the bundled Freemius SDK in all versions up to, and including, 4.9.5. This is due to the pricing app configuration being built by merging request query parameters over trusted values such as plugin_id, mode, fs_wp_endpoint_url and request_handler_url before they are passed to the inline pricing script. This makes it possible for unauthenticated attackers to point the pricing page's requests and checkout redirects at attacker-controlled URLs if they can trick a site administrator into opening a crafted link and acting on the page.

## References

- https://wpsec.com/vuln/WPSEC-2026-0759/
- https://plugins.svn.wordpress.org/all-in-one-video-gallery/tags/4.9.7/
- https://wordpress.org/plugins/all-in-one-video-gallery/

Source: WPSec, https://wpsec.com/vuln/WPSEC-2026-0759/

License: CC BY 4.0 (https://creativecommons.org/licenses/by/4.0/). Free to use, share and adapt, also commercially, if you credit WPSec and link to this advisory.
