CVE-2026-19075 PUBLISHED

All-in-One Video Gallery < 4.9.2 - Subscriber+ Server-Side Request Forgery via 'vdl' Parameter

Assigner: WPScan
Reserved: 06.08.2026 Published: 10.08.2026 Updated: 10.08.2026

All-in-One Video Gallery registers a public, unauthenticated file-download handler triggered by ?vdl=<post_id> on any aiovg_videos post (public/video.php, AIOVG_Public_Video::download_video()), which reads the post's mp4 meta value and streams that URL's response back to the requester.

Product Status

Vendor Unknown
Product All-in-One Video Gallery
Versions Default: unaffected
  • affected from 0 to 4.9.2 (excl.)

Credits

  • Mohammed Abd Alrahman finder
  • WPScan coordinator

References

Problem Types

  • CWE-918 Server-Side Request Forgery (SSRF) CWE