All-in-One Video Gallery <= 4.9.5 - Authenticated (Subscriber+) Server-Side Request Forgery via Featured Image Download

Medium 6.4 CWE-918Fixed in 4.9.7
ID
WPSEC-2026-0760
Plugin
All-in-One Video Gallery – Video Player & Galleries for YouTube, Vimeo & Self-Hosted Videos (all-in-one-video-gallery)
Affected
all versions before 4.9.7
Remediation
Update to 4.9.7 or later.
CVSS 3.1
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N
Weakness
CWE-918
Usage
Plugin Medium · Affected versions Low among sites WPSec scans, 2026-10-11
Attack surface
All-in-One Video Gallery on WPSec AttackSurface
Fix released
Published

Description

The All-in-One Video Gallery plugin for WordPress is vulnerable to Server-Side Request Forgery via the external featured image download in all versions up to, and including, 4.9.5. This is due to the aiovg_create_attachment_from_external_image_url() function requesting the user-supplied poster image URL with wp_remote_head() and then fetching it with file_get_contents() without restricting the destination host, validating redirects or pinning the resolved IP address, and accepting the remote Content-Type header as proof that the content is an image. This makes it possible for authenticated attackers, with subscriber-level access and above (the plugin grants the edit_aiovg_videos capability to subscribers), to make the server send requests to arbitrary locations, including internal services, and to have the response saved to the site's public uploads directory. The 'Featured Images' option must be enabled, and 'Download External Images' must be left on, which is the default.

References

Published by WPSec. Provided as is, without warranty. Corrections: contact us.

This advisory as JSON or Markdown · All advisories: JSON, RSS

License: CC BY 4.0