The WordPress plugin called All-in-One Video Gallery has a security issue that allows attackers to upload any type of file to a website. This problem affects all versions up to 3.6.4 and can be exploited by anyone with contributor access or higher. This could potentially allow them to run code on the website’s server.