Unauthorized Data Modification in All-in-One Video Gallery Plugin for WordPress
CVE-2025-14947
6.5MEDIUM
What is CVE-2025-14947?
The All-in-One Video Gallery plugin for WordPress suffers from a vulnerability that allows unauthorized modification of data due to inadequate capability checks. This issue affects the functions responsible for handling Bunny Stream video content, enabling unauthenticated attackers to create and delete videos associated with victim accounts if they can obtain a valid nonce. This nonce is unfortunately exposed in public player templates, significantly increasing the risk of exploitation.
Affected Version(s)
All-in-One Video Gallery 0 <= 4.6.4