Plugins360 develops a niche WordPress plugin focused on video gallery functionality, with a recurring vulnerability pattern centered on web-application input-handling and access-control weaknesses such as path traversal, cross-site scripting, and missing authorization checks. The exposure reflects typical risks in plugin-based content management where boundary enforcement between user roles and file access becomes a structural concern for defenders managing WordPress deployments. Live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Plugins360 over time
Signals from CVEs in this vendor scope (12 CVEs).
12 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2022-2633HIGH The All-in-One Video Gallery plugin for WordPress is vulnerable to arbitrary file downloads and blind server-side request forgery via the 'dl' parameter found in the ~/public/video | Sep 6, 2022 | 8.2 | 48 | NO | YES |
CVE-2021-24970HIGH The All-in-One Video Gallery WordPress plugin before 2.5.0 does not sanitise and validate the tab parameter before using it in a require statement in the admin dashboard, leading t | Dec 13, 2021 | 7.2 | 36 | NO | YES |
CVE-2025-12957HIGH The All-in-One Video Gallery plugin for WordPress is vulnerable to arbitrary file upload in all versions up to, and including, 4.5.7. This is due to insufficient file type validati | Jan 16, 2026 | 8.8 | 31 | NO | NO |
CVE-2026-12123MEDIUM The All-in-One Video Gallery plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 4.8.5 via the 'vdl' parameter. This makes it po | Jul 10, 2026 | 6.4 | 30 | NO | NO |
CVE-2025-12966HIGH The All-in-One Video Gallery plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the resolve_import_directory() function in versions | Dec 6, 2025 | 8.8 | 29 | NO | NO |
CVE-2024-4670HIGH The All-in-One Video Gallery plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 3.6.5 via the aiovg_search_form shortcode. This makes | May 15, 2024 | 8.8 | 26 | NO | NO |
CVE-2024-31248HIGH Missing Authorization vulnerability in Team Plugins360 All-in-One Video Gallery.This issue affects All-in-One Video Gallery: from n/a through 3.5.2. | Jun 9, 2024 | 8.8 | 24 | NO | NO |
CVE-2024-4033HIGH The All-in-One Video Gallery plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the aiovg_create_attachment_from_external_image_url | May 2, 2024 | 8.8 | 24 | NO | NO |
CVE-2026-1706MEDIUM The All-in-One Video Gallery plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'vi' parameter in all versions up to, and including, 4.7.1 due to insuffic | Mar 4, 2026 | 6.1 | 23 | NO | NO |
CVE-2025-14947MEDIUM The All-in-One Video Gallery plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the `ajax_callback_create_bunny_stream_vid | Jan 23, 2026 | 6.5 | 22 | NO | NO |
Signals from CVEs in this vendor scope (12 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Plugins360.
Media articles that mention a CVE ID that affects a product developed by Plugins360 — matched by CVE ID, not by vendor name.