PT-2026-69381 · WordPress · All-In-One Video Gallery

CVE-2026-19075

·

Published

2026-08-10

·

Updated

2026-08-10

CVSS v3.1

5.0

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:C/C:L/I:N/A:N
Name of the Vulnerable Software and Affected Versions All-in-One Video Gallery versions prior to 4.9.2
Description The software implements a public, unauthenticated file-download handler that allows Server-Side Request Forgery (SSRF). This occurs when the AIOVG Public Video::download video() function in the public/video.php file processes the vdl parameter on any aiovg videos post. The system reads the mp4 meta value of the post and streams the response from that URL back to the requester.
Recommendations Update All-in-One Video Gallery to version 4.9.2 or later. As a temporary mitigation, restrict access to the vdl parameter in the public/video.php endpoint.

Exploit

Fix

SSRF

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-19075

Affected Products

All-In-One Video Gallery