Skip to content

Known CVE

All-In-One Video Gallery <=2.6.0 - Server-Side Request Forgery

WordPress All-in-One Video Gallery plugin through 2.6.0 is susceptible to arbitrary file download and server-side request forgery (SSRF) via the 'dl' parameter found in the ~/public/video.php file. An attacker can download sensitive files hosted on the affected server and forge requests to the server.

CVE-2022-2633

High2022CVSS 8.2CWE-610

cve2022 · wp-plugin · unauth · ssrf · wpscan · wordpress · wp · all-in-one-video-gallery

Verified scans run this check after you prove you own the site.

All known CVEsView the checks catalogNational Vulnerability Database

Scan a website