All-in-One Video Gallery
cpe:2.3:a:plugins360:all-in-one_video_gallery:*:*:*:*:wordpress:*:*
- >= 4.1.0, <= 4.6.4
A vulnerability exists in the All-in-One Video Gallery plugin for WordPress, specifically in versions 4.1.0 to 4.6.4. The issue arises from a lack of proper capability checks in the 'ajax_callback_store_user_meta()' function, which allows authenticated users with Subscriber-level access and above to arbitrarily modify string-based user meta keys for their own accounts. This unauthorized data manipulation could lead to various issues, depending on the meta keys altered.
Exploitation of this vulnerability could result in unauthorized changes to user meta data, potentially allowing attackers to manipulate information that could affect their privileges or the functionality of the site.
Users are advised to update the All-in-One Video Gallery plugin to version 4.7.1 or a newer patched version.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.