PT-2026-3212 · WordPress · All-In-One Video Gallery

Michael Mazzolini

·

Publicado

2026-01-16

·

Atualizado

2026-01-17

·

CVE-2025-12957

CVSS v3.1

8.8

Alta

VetorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions All-in-One Video Gallery plugin for WordPress versions prior to 4.5.8
Description The All-in-One Video Gallery plugin for WordPress is susceptible to arbitrary file upload due to inadequate file type validation when handling VTT files. This allows attackers to bypass sanitization by using double extension files, potentially leading to remote code execution. The issue affects authenticated attackers with author-level access or higher. The vulnerability stems from the plugin’s acceptance of files as valid VTT files without proper checks, enabling the upload of arbitrary files to the server.
Recommendations Update the All-in-One Video Gallery plugin to version 4.5.8 or later.

Correção

Unrestricted File Upload

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2025-12957

Produtos afetados

All-In-One Video Gallery