S4E just found a high-severity finding from top 10 tcp port service scan
PlatformPlansPartners
Resources
ToolsBlogDocs
Sign Up →
high·Product Based Web Vulnerabilities·Updated Jan 3, 2024

CVE-2022-2633 Scanner

CVE-2022-2633 scanner - Server-Side-Request-Forgery (SSRF) vulnerability in All-in-One Video Gallery plugin for WordPress

Est. Time~10 seconds
Scan TypeSingle Scan
Targetsdomain, ipv4, subdomain
CostFree
2k
Times Used
continuous scan runs
4.7k
Continuously Checked
assets under CS
0
Vulnerabilities Found
confirmed findings
References
CVECVE-2022-2633
8.2
CVSShigh
Exploitable remotely over the internet · no authentication required.

The All-in-One Video Gallery plugin for WordPress is vulnerable to arbitrary file downloads and blind server-side request forgery via the 'dl' parameter found in the ~/public/video.php file in versions up to, and including 2.6.0. This makes it possible for unauthenticated users to download sensitive files hosted on the affected server and forge requests to the server.

Attack Vector
Network
Privileges Req.
None
User Interaction
None
Affected
All-in-One Video Galleryby plugins360
2.5.8
Updated Aug 22, 2026View on NVD →
Detail

The All-in-One Video Gallery plugin for WordPress is a widely used tool for website owners to display video content on their websites. It boasts features such as customizable layouts, video previews, social media integration, and compatibility with multiple video platforms. Essentially, it provides a comprehensive solution for businesses and individuals looking to showcase their multimedia content on their WordPress site.

However, recently a concerning security flaw has been identified in this plugin's code. CVE-2022-2633 is a vulnerability that allows attackers to download sensitive files from the server and even make requests to the server. The security issue lies within the 'dl' parameter found in the ~/public/video.php file. This has caused concern and underscores the importance of remaining vigilant about website security.

When exploited, this vulnerability could have unwanted consequences for WordPress site owners. Attackers could gain access to confidential and sensitive information, potentially leaving user data exposed. Not only that, but the compromised server could be used as a launchpad for further attacks.

At S4E, we take security seriously. Our platform's pro features can quickly and easily scan websites for vulnerabilities. Website owners can take advantage of our advanced tools to understand their assets' current security state. We invite everyone to take a proactive approach to security and protect their digital assets from threats like CVE-2022-2633.

 

REFERENCES

Solution Advice

Luckily, there are steps that can be taken to protect against this vulnerability. Here are some precautions that website owners can take to prevent malicious actors from exploiting CVE-2022-2633: 

  • Update the All-in-One Video Gallery plugin to the latest version that fixes the issue.
  • Remove any files that could be at risk of being downloaded.
  • Utilize a web application firewall (WAF) to detect and block suspicious traffic.
  • Monitor traffic and logs for any suspicious activity.
  • Practice strong password hygiene to prevent unauthorized access.

Get AI-powered remediation steps tailored to your asset.

Try AI Solutions →

Check your infrastructure.
Right now.

11,000+ scanners. Free to start. No credit card required.