Review
All-in-One Video Gallery
CVE published 2026-08-10
CVE-2026-19075
AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-08-10T07:16:51.260Z and has not been modified since then. The All-in-One Video Gallery plugin has a public, unauthenticated file-download handler triggered by `?vdl=<post_id>` on any `aiovg_videos` post (`public/video.php`, `AIOVG_Public_Video::download_video()`), which reads the post's `mp4` meta valu [truncated]