PT-2026-3212 · WordPress · All-In-One Video Gallery

Michael Mazzolini

·

Published

2026-01-16

·

Updated

2026-01-17

·

CVE-2025-12957

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions All-in-One Video Gallery plugin for WordPress versions prior to 4.5.8
Description The All-in-One Video Gallery plugin for WordPress is susceptible to arbitrary file upload due to inadequate file type validation when handling VTT files. This allows attackers to bypass sanitization by using double extension files, potentially leading to remote code execution. The issue affects authenticated attackers with author-level access or higher. The vulnerability stems from the plugin’s acceptance of files as valid VTT files without proper checks, enabling the upload of arbitrary files to the server.
Recommendations Update the All-in-One Video Gallery plugin to version 4.5.8 or later.

Fix

Unrestricted File Upload

Weakness Enumeration

Related Identifiers

CVE-2025-12957

Affected Products

All-In-One Video Gallery