All Video Gallery Plugin for WordPress
Vulnerable and lacking (2 posts)

  1. kimosiris
    Posted 3 years ago #

    This plugin has a vulnerability. Someone was able to access my admin account and change the password using the following which goes on much longer than shown with a whole bunch of numbers at the end.

    wp-content/plugins/all-video-gallery/config.php?vid=7&pid=1 union select 1,2,3,4,group_concat(user_login,0x3a,user_pass),

    It is also lacking in a basic function to create playlists from the videos.

    There is also an error creating the Youtube thumbnail so the thumbnail is blank

  2. Vinoth Kumar
    Plugin Author

    Posted 3 years ago #

    Regarding Vulnerability,

    Actually, we had this issue in our 1.1 version and have solved in 1.2 version. Did you checked it ?

    Regarding YouTube thumbnail issue,

    Kindly check http://allvideogallery.mrvinoth.com/forum/7-adding-videos/876-youtube?limit=6&start=6#885

Topic Closed

This topic has been closed to new replies.

About this Plugin

About this Topic


No tags yet.