CVE-2022-2633 is a critical vulnerability affecting the All-in-One Video Gallery plugin for WordPress, specifically versions up to and including 2.6.0. It allows unauthenticated attackers to perform arbitrary file downloads and blind server-side request forgery (SSRF) through the 'dl' parameter in the ~/public/video.php file. With a CVSS score of 8.2 (HIGH), this vulnerability is easily exploitable over the network with low attack complexity, potentially leading to the disclosure of sensitive server files and the ability to forge server requests. While not currently listed in CISA's KEV catalog, Nuclei templates exist for detecting this SSRF vulnerability, indicating readily available exploit code, though there is minimal community discussion or media coverage surrounding it.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 2.5.8, <= 2.6.0CPE matchmatch criteria | cpe:2.3:a:plugins360:all-in-one_video_gallery:*:*:*:*:*:wordpress:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.