The All-in-One Video Gallery plugin for WordPress has a security flaw in versions up to and including 2.6.0. This flaw means that people who do not have permission to access the server can download sensitive files and make requests to the server. The flaw is in the ‘dl’ parameter found in the ~/public/video.php file.