Description
WordPress Plugin All-in-One Video Gallery is prone to a local file inclusion vulnerability because it fails to sufficiently verify user-supplied input. Exploiting this issue may allow an attacker to obtain sensitive information that could aid in further attacks. WordPress Plugin All-in-One Video Gallery version 2.4.9 is vulnerable; prior versions may also be affected.
Remediation
Update to plugin version 2.5.0 or latest
References
https://m19o.github.io/posts/How-i-found-my-first-0day/
https://www.exploit-db.com/exploits/50562
https://sploitus.com/exploit?id=1337DAY-ID-37097
https://plugins.svn.wordpress.org/all-in-one-video-gallery/trunk/README.txt
Related Vulnerabilities
WordPress Plugin Spicy Blogroll Local File Include (1.0.0)
WordPress Plugin User Activity Log Multiple Vulnerabilities (1.2.4)
WordPress Plugin Classified Listing Store & Membership Cross-Site Scripting (1.4.19)
WordPress Plugin GiveWP-Donation and Fundraising Platform Information Disclosure (2.20.2)