CVE-2026-19075
All-in-One Video Gallery < 4.9.2 - Subscriber+ Server-Side Request Forgery via 'vdl' Parameter
CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th
All-in-One Video Gallery registers a public, unauthenticated file-download handler triggered by `?vdl=<post_id>` on any `aiovg_videos` post (`public/video.php`, `AIOVG_Public_Video::download_video()`), which reads the post's `mp4` meta value and streams that URL's response back to the requester.
| Vendor | unknown |
| Product | all-in-one video gallery |
| Published | Aug 10, 2026 |
Stay Ahead of the Next One
Get instant alerts for unknown all-in-one video gallery
Be the first to know when new unknown vulnerabilities affecting unknown all-in-one video gallery are published โ delivered to Slack, Telegram or Discord.
Get Free Alerts โ
Free ยท No credit card ยท 60 sec setup
Affected Versions
Unknown / All-in-One Video Gallery
0 < 4.9.2
References
Credits
Mohammed Abd Alrahman WPScan