Description
WordPress Plugin All-in-One Video Gallery is prone to multiple vulnerabilities, including arbitrary file download and server-side request forgery vulnerabilities. Exploiting these issues may allow an attacker to gain access to sensitive information, which may aid in launching further attacks, or to make the vulnerable server perform port scanning of hosts in internal or external networks; other attacks are also possible. WordPress Plugin All-in-One Video Gallery versions 2.5.8 - 2.6.0 are vulnerable.
Remediation
Update to plugin version 2.6.1 or latest
References
https://www.wordfence.com/vulnerability-advisories/#CVE-2022-2633
https://plugins.svn.wordpress.org/all-in-one-video-gallery/trunk/README.txt
Related Vulnerabilities
WordPress Plugin bizzCam Video Cross-Site Scripting (0.1)
Oracle Database Server CVE-2020-2737 Vulnerability (CVE-2020-2737)
WordPress Plugin WP Advanced Importer Cross-Site Scripting (2.1.1)
WordPress Plugin Google Maps Cross-Site Scripting (2.1.3)
Apache HTTP Server Resource Management Errors Vulnerability (CVE-2016-1546)