Access violation vulnerability in All-in-One Video Gallery 2.6.0

The All-in-One Video Gallery plugin for WordPress has a security flaw in versions up to and including 2.6.0. This flaw means that people who do not have permission to access the server can download sensitive files and make requests to the server. The flaw is in the ‘dl’ parameter found in the ~/public/video.php file.

Detected in:

All-in-One Video Gallery fixed vulnerable versions: >= 2.5.8 <= 2.6.0

This information is sourced from www.wpvulnerability.com. An open-source database of vulnerabilities maintained by the community. Help us out by submitting vulnerabilities!

Version compare shows which versions have a vulnerability. For example: >= 2.2.8 <= 2.2.21 means:

> from 2.2.8
= including 2.2.8 & 2.2.21
< to 2.2.21

Is this information incorrect? Please leave us a message.