Description
WordPress Plugin All-in-One Video Gallery is prone to a local file inclusion vulnerability because it fails to sufficiently verify user-supplied input. Exploiting this issue may allow an attacker to obtain sensitive information that could aid in further attacks. WordPress Plugin All-in-One Video Gallery version 2.4.9 is vulnerable; prior versions may also be affected.
Remediation
Update to plugin version 2.5.0 or latest
References
https://m19o.github.io/posts/How-i-found-my-first-0day/
https://www.exploit-db.com/exploits/50562
https://sploitus.com/exploit?id=1337DAY-ID-37097
https://plugins.svn.wordpress.org/all-in-one-video-gallery/trunk/README.txt
Related Vulnerabilities
Apache Tomcat Insufficient Verification of Data Authenticity Vulnerability (CVE-2017-7674)
Oracle Application Server Other Vulnerability (CVE-2002-0569)
WordPress Plugin Product Addons & Fields for WooCommerce Cross-Site Scripting (32.0.6)
Ampache Unrestricted Upload of File with Dangerous Type Vulnerability (CVE-2022-4665)
IBM WebSEAL Inadequate Encryption Strength Vulnerability (CVE-2018-1814)