Description
The All-in-One Video Gallery plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the ajax_callback_store_user_meta() function in versions 4.1.0 to 4.6.4. This makes it possible for authenticated attackers, with Subscriber-level access and above, to update arbitrary string-based user meta keys for their own account.
Problem types
Product status
4.1.0 (semver)
Timeline
| 2025-12-30: | Discovered |
| 2026-01-13: | Vendor Notified |
| 2026-01-23: | Disclosed |
Credits
Kenneth Dunn
References
www.wordfence.com/...-661b-49e1-8b23-457a93fd53fa?source=cve
plugins.trac.wordpress.org/...ery/tags/4.6.4/admin/admin.php