All-in-One Video Gallery <= 4.9.5 - Authenticated (Subscriber+) Server-Side Request Forgery via Featured Image Download
- ID
- WPSEC-2026-0760
- Plugin
- All-in-One Video Gallery – Video Player & Galleries for YouTube, Vimeo & Self-Hosted Videos (all-in-one-video-gallery)
- Affected
- all versions before 4.9.7
- Remediation
- Update to 4.9.7 or later.
- CVSS 3.1
- CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N
- Weakness
- CWE-918
- Usage
- Plugin Medium · Affected versions Low among sites WPSec scans, 2026-10-11
- Attack surface
- All-in-One Video Gallery on WPSec AttackSurface
- Fix released
- Published
Description
The All-in-One Video Gallery plugin for WordPress is vulnerable to Server-Side Request Forgery via the external featured image download in all versions up to, and including, 4.9.5. This is due to the aiovg_create_attachment_from_external_image_url() function requesting the user-supplied poster image URL with wp_remote_head() and then fetching it with file_get_contents() without restricting the destination host, validating redirects or pinning the resolved IP address, and accepting the remote Content-Type header as proof that the content is an image. This makes it possible for authenticated attackers, with subscriber-level access and above (the plugin grants the edit_aiovg_videos capability to subscribers), to make the server send requests to arbitrary locations, including internal services, and to have the response saved to the site's public uploads directory. The 'Featured Images' option must be enabled, and 'Download External Images' must be left on, which is the default.
References
- https://wpsec.com/vuln/WPSEC-2026-0760/
- https://plugins.svn.wordpress.org/all-in-one-video-gallery/tags/4.9.7/
- https://wordpress.org/plugins/all-in-one-video-gallery/
Published by WPSec. Provided as is, without warranty. Corrections: contact us.
This advisory as JSON or Markdown · All advisories: JSON, RSS