N/A
2026-03-03< 4.7.5
All-in-One Video Gallery <= 4.7.1 - Reflected Cross-Site Scripting via 'vi' Parameter
Minimum safe version
4.7.5
Update to 4.7.5 or later to address 16 fixable vulnerabilities
All-in-One Video Gallery <= 4.7.1 - Reflected Cross-Site Scripting via 'vi' Parameter
CVE-2025-14947
CVE-2025-15516
CVE-2025-12957
CVE-2025-12966
Freemius SDK <= 2.4.2 - Missing Authorization Checks
CVE-2024-6629
CVE-2024-4670
CVE-2024-4033
CVE-2024-31248
WordPress All-in-One Video Gallery Plugin < 3.4.3 is vulnerable to Cross Site Scripting (XSS)
Freemius SDK <= 2.4.2 - Missing Authorization Checks
CVE-2022-2633
WordPress All-in-One Video Gallery plugin < 2.5.4 - Sensitive Information Disclosure vulnerability
WordPress All-in-One Video Gallery plugin < 2.5.4 - Toggle The Debug Mode via Cross-Site Request Forgery (CSRF) vulnerability
CVE-2021-24970