Description
WordPress Plugin All-in-One Video Gallery is prone to a local file inclusion vulnerability because it fails to sufficiently verify user-supplied input. Exploiting this issue may allow an attacker to obtain sensitive information that could aid in further attacks. WordPress Plugin All-in-One Video Gallery version 2.4.9 is vulnerable; prior versions may also be affected.
Remediation
Update to plugin version 2.5.0 or latest
References
https://m19o.github.io/posts/How-i-found-my-first-0day/
https://www.exploit-db.com/exploits/50562
https://sploitus.com/exploit?id=1337DAY-ID-37097
https://plugins.svn.wordpress.org/all-in-one-video-gallery/trunk/README.txt