PT-2025-49357 · WordPress · All-In-One Video Gallery

Kenneth Dunn

·

Published

2025-12-06

·

Updated

2025-12-11

·

CVE-2025-12966

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions All-in-One Video Gallery versions 4.5.4 through 4.5.7
Description The All-in-One Video Gallery plugin for WordPress has a flaw that allows unauthorized file uploads. This is due to a lack of proper file type checking within the resolve import directory() function. Attackers with Author-level access or higher can upload any file type to the server, potentially leading to remote code execution. The vulnerable parameter is the file being uploaded through the import directory functionality.
Recommendations Update to a version of All-in-One Video Gallery that addresses this issue.

Fix

RCE

Unrestricted File Upload

Weakness Enumeration

Related Identifiers

CVE-2025-12966

Affected Products

All-In-One Video Gallery