plugins360 records
5 published records for vendor plugins360.
Researcher profile
- Entered KEV
- 0 · 0%
- Weaponized
- 0 · 0%
- Pre-auth RCE
- 0
- With a fix record
- 20%
- Median publish → KEV
- No record has entered KEV
Recurring classes
- CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')1
- CWE-610 Externally Controlled Reference to a Resource in Another Sphere1
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')1
- CWE-862 Missing Authorization1
- CWE-98 Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion')1
The weakness classes this vendor ships most often: where to look.
CWEAll records
5 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
42Plan | CVE-2022-2633Proof of concept | The All-in-One Video Gallery plugin for WordPress is vulnerable to arbitrary file downloads and blind server-side request forgery via the 'dplugins360 · all-in-one video gallery · CWE-610 | High8.2 | — | 33.8% | Sep 6, 2022 |
35Monitor | CVE-2024-4670No exploit | All-in-One Video Gallery <= 3.6.5 - Authenticated (Contributor+) Local File Inclusion via aiovg_search_form Shortcodeplugins360 · all-in-one video gallery · CWE-98 | High8.8 | — | 0.6% | May 15, 2024 |
35Monitor | CVE-2024-31248No exploit | WordPress All-in-One Video Gallery plugin <= 3.5.2 - Broken Access Control vulnerabilityplugins360 · all-in-one video gallery · CWE-862 | High8.8 | — | 0.4% | Jun 9, 2024 |
30Monitor | CVE-2021-24970Proof of concept | All-In-One-Gallery < 2.5.0 - Admin+ Local File Inclusionplugins360 · all-in-one video gallery · CWE-22 | High7.2 | — | 5.9% | Dec 13, 2021 |
21Monitor | CVE-2024-6629No exploit | All-in-One Video Gallery <= 3.7.1 - Authenticated (Contributor+) Stored Cross-Site Scripting via Video Shortcodeplugins360 · all-in-one video gallery · CWE-79 | Medium5.4 | — | 0.3% | Jul 24, 2024 |
- CVE-2022-263342Plan
The All-in-One Video Gallery plugin for WordPress is vulnerable to arbitrary file downloads and blind server-side request forgery via the 'd
HighCVSS 8.2Proof of conceptEPSS 34%plugins360 · all-in-one video gallerySep 6, 2022
- CVE-2024-467035Monitor
All-in-One Video Gallery <= 3.6.5 - Authenticated (Contributor+) Local File Inclusion via aiovg_search_form Shortcode
HighCVSS 8.8No exploitEPSS 1%plugins360 · all-in-one video galleryMay 15, 2024
- CVE-2024-3124835Monitor
WordPress All-in-One Video Gallery plugin <= 3.5.2 - Broken Access Control vulnerability
HighCVSS 8.8No exploitEPSS 0%plugins360 · all-in-one video galleryJun 9, 2024
- CVE-2021-2497030Monitor
All-In-One-Gallery < 2.5.0 - Admin+ Local File Inclusion
HighCVSS 7.2Proof of conceptEPSS 6%plugins360 · all-in-one video galleryDec 13, 2021
- CVE-2024-662921Monitor
All-in-One Video Gallery <= 3.7.1 - Authenticated (Contributor+) Stored Cross-Site Scripting via Video Shortcode
MediumCVSS 5.4No exploitEPSS 0%plugins360 · all-in-one video galleryJul 24, 2024