Junglewise Threat Intelligence

CVE-2026-19075: All-in-One Video Gallery server-side request forgery via vdl parameter

CVE-2026-19075 · Severity: medium · CVSS 5 · Published 2026-08-10

Executive brief

All-in-One Video Gallery is a WordPress plugin that allows site administrators to manage video content. The plugin contains a server-side request forgery (SSRF) vulnerability in its file-download handler that allows authenticated users with Subscriber privileges to bypass security controls and access internal services or metadata on the same server, exposing sensitive information like configuration data or cloud credentials.

Technical details

All-in-One Video Gallery registers an unauthenticated file-download handler triggered by the `?vdl=<post_id>` parameter on any `aiovg_videos` post, which streams the URL specified in a post's `mp4` meta value back to the requester. A previous attempt to patch SSRF vulnerabilities in version 4.9.0 introduced new validation functions but left two independent bypasses intact. Bypass A exploits a same-host allowlist that compares only hostname, not port, allowing requests to internal services on different ports of the same host. Bypass B uses DNS rebinding—the validation function resolves a hostname once to check the IP, but then makes separate DNS resolutions for each subsequent request (via `get_headers()` and `fopen()`) without pinning to the originally validated IP, allowing TTL=0 DNS answers to swap in private IPs after validation passes. Both bypasses require Subscriber-level access to inject the malicious URL into a video's metadata (a capability the plugin grants to subscribers by design), but the download trigger itself requires no authentication. An attacker can fully disclose HTTP response bodies from internal services and perform reliable port scanning.

Affected products

  • Elvis All-in-One Video Gallery before 4.9.2

Timeline

  • 2026-08-10: disclosed

References