
All-in-One Video Gallery Security & Risk Analysis
wordpress.org/plugins/all-in-one-video-galleryVideo gallery plugin for WordPress with a built-in HTML5 player. Embed YouTube, Vimeo, Dailymotion, Rumble, and self-hosted videos.
Is All-in-One Video Gallery Safe to Use in 2026?
Generally Safe
Score 88/100All-in-One Video Gallery has a strong security track record. Known vulnerabilities have been patched promptly. It's a solid choice for most WordPress installations.
The "all-in-one-video-gallery" plugin v4.7.5 presents a mixed security posture. While it demonstrates good practices in SQL query sanitization and a high percentage of properly escaped output, significant concerns arise from its attack surface. A substantial number of AJAX handlers (23 out of 24) lack proper authorization checks, creating a wide entry point for potential privilege escalation or unauthorized actions. Furthermore, the taint analysis, while not revealing critical or high severity issues in this scan, did identify flows with unsanitized paths, indicating a potential for path traversal vulnerabilities if these flows are triggered by user input.
The plugin's historical vulnerability data is a major red flag. A total of 11 known CVEs, with 6 high and 5 medium severity, suggests a pattern of recurring security weaknesses. The common vulnerability types listed (XSS, Missing Authorization, Unrestricted Upload, Path Traversal, PHP Remote File Inclusion) are all severe and can lead to complete site compromise. The fact that there are currently no unpatched CVEs is a positive, but the sheer volume and nature of past vulnerabilities point to a plugin that has historically been a target and may have underlying architectural issues that are difficult to fully remediate. The last vulnerability being in 2026 is likely a typo and should be treated with caution.
In conclusion, despite some positive technical indicators like prepared SQL statements and good output escaping, the substantial number of unprotected AJAX endpoints and the plugin's extensive history of high and medium severity vulnerabilities necessitate a cautious approach. Users should be aware of the potential risks associated with the broad attack surface and the historical pattern of exploitable flaws, even if the current version appears to have addressed past issues.
Key Concerns
- Large attack surface without auth checks (AJAX)
- Unsanitized paths in taint analysis
- History of 6 High severity CVEs
- History of 5 Medium severity CVEs
- Missing authorization on 23 AJAX handlers
- Bundled outdated library (Freemius v1.0)
All-in-One Video Gallery Security Vulnerabilities
CVEs by Year
Severity Breakdown
12 total CVEs
All-in-One Video Gallery <= 4.8.5 - Authenticated (Subscriber+) Server-Side Request Forgery via 'vdl' Parameter
All-in-One Video Gallery <= 4.7.1 - Reflected Cross-Site Scripting via 'vi' Parameter
All-in-One Video Gallery 4.1.0 - 4.6.4 - Missing Authorization to Authenticated (Subscriber+) Limited User Meta Update
All-in-One Video Gallery <= 4.6.4 - Missing Authorization to Unauthenticated Bunny Stream Video Creation/Deletion
All-in-One Video Gallery <= 4.5.7 - Authenticated (Author+) Arbitrary File Upload via VTT Upload Bypass
All-in-One Video Gallery 4.5.4 - 4.5.7 – Authenticated (Author+) Arbitrary File Upload via Import ZIP
All-in-One Video Gallery <= 3.7.1 - Authenticated (Contributor+) Stored Cross-Site Scripting via Video Shortcode
All-in-One Video Gallery <= 3.6.5 - Authenticated (Contributor+) Local File Inclusion via aiovg_search_form Shortcode
All-in-One Video Gallery <= 3.6.4 - Authenticated (Contributor+) Arbitrary File Upload via featured image
All-in-One Video Gallery <= 3.5.2 - Missing Authorization
All-in-One Video Gallery 2.5.8 - 2.6.0 - Arbitrary File Download & Server-Side Request Forgery
All-In-One-Gallery <= 2.4.9 - Admin+ Local File Inclusion
All-in-One Video Gallery Release Timeline
All-in-One Video Gallery Code Analysis
Bundled Libraries
SQL Query Safety
Output Escaping
Data Flow Analysis
All-in-One Video Gallery Attack Surface
AJAX Handlers 24
Shortcodes 12
WordPress Hooks 126
Scheduled Events 1
Maintenance & Trust
All-in-One Video Gallery Maintenance & Trust
Maintenance Signals
Community Trust
All-in-One Video Gallery Alternatives
Video gallery and Player
html5-videogallery-plus-player
Easy to add and display your HTML5, YouTube, Vimeo vedio gallery with Magnific Popup to your website. Also work with Gutenberg shortcode block.
Video Gallery – YouTube, Vimeo Gallery & YouTube API
new-video-gallery
Create video portfolio with YouTube and Vimeo video galleries. Features YouTube API integration, lightbox popup player, and grid layouts.
Simple Video Post
simple-video-post
A simple video post plugin that support YouTube/Vimeo/Facebook/Dailymotion like video sharing website. No coding required.
Presto Player
presto-player
A modern video and audio player for courses, landing pages, marketing, and testimonials — with captions, branding, and page-builder support.
FV Flowplayer Video Player
fv-wordpress-flowplayer
WordPress's most reliable, easy to use and feature-rich video player. Supports responsive design, HTML5, playlists, ads, stats, Vimeo and YouTube.
All-in-One Video Gallery Developer Profile
3 plugins · 29K total installs
How We Detect All-in-One Video Gallery
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/all-in-one-video-gallery/public/assets/css/all-in-one-video-gallery.css/wp-content/plugins/all-in-one-video-gallery/public/assets/js/all-in-one-video-gallery.js/wp-content/plugins/all-in-one-video-gallery/public/assets/js/all-in-one-video-gallery.jsall-in-one-video-gallery/public/assets/css/all-in-one-video-gallery.css?ver=all-in-one-video-gallery/public/assets/js/all-in-one-video-gallery.js?ver=HTML / DOM Fingerprints
aiovg-gallery-container<!-- AIOVG: START SINGLE VIDEO --><!-- AIOVG: END SINGLE VIDEO -->data-aiovg-gallery-iddata-aiovg-playlist-idAIOVG_GLOBAL_SETTINGSaiovg_settings/wp-json/aiovg/v1/gallery[all_in_one_video_gallery]