S4E just found a high-severity finding from top 10 tcp port service scan
PlatformPlansPartners
Resources
ToolsBlogDocs
Sign Up →
high·Product Based Web Vulnerabilities·Updated Feb 23, 2024

CVE-2021-24970 Scanner

Detects 'Local File Inclusion (LFI)' vulnerability in All-In-One Video Gallery plugin for WordPress affects v. before 2.5.0.

Est. Time~10 seconds
Scan TypeSingle Scan
Targetsdomain, ipv4, subdomain
CostFree
3.3k
Times Used
continuous scan runs
4.2k
Continuously Checked
assets under CS
0
Vulnerabilities Found
confirmed findings
References
CVECVE-2021-24970
7.2
CVSS

The All-in-One Video Gallery WordPress plugin before 2.5.0 does not sanitise and validate the tab parameter before using it in a require statement in the admin dashboard, leading to a Local File Inclusion issue

Attack Vector
-
Privileges Req.
-
User Interaction
-
Affected
All-in-One Video Gallery
AFFECTED< 2.5.0SAFE ✓≥ 2.5.0
Updated Aug 21, 2026View on NVD →
Detail

Vulnerability Overview

The vulnerability arises from the plugin's failure to adequately sanitize and validate user inputs before including files. This oversight allows for the inclusion of arbitrary files stored on the server, potentially leading to sensitive information disclosure.

Vulnerability Details

Specifically, the issue is found within the admin dashboard of the All-in-One Video Gallery plugin. The 'tab' parameter is mishandled, enabling attackers with administrative access to exploit the vulnerability by navigating to a crafted URL that includes sensitive system files.

Possible Effects

Exploiting this vulnerability can lead to:

  • Unauthorized access to sensitive files on the server.
  • Disclosure of sensitive information such as credentials, system configuration details, and more.
  • Potentially leveraging the disclosed information for further attacks against the system or network.

Why Choose S4E

At S4E, we offer cutting-edge solutions for detecting and managing vulnerabilities like CVE-2021-24970. Our platform provides:

  • Comprehensive vulnerability assessments tailored to your needs.
  • Timely alerts and updates on new and emerging threats.
  • Expert support to guide you through remediation processes. Join S4E today and fortify your cybersecurity defenses against evolving threats.

References

Solution Advice
  • Immediate Update: Upgrade to All-In-One Video Gallery version 2.5.4 or later.
  • Access Control: Limit admin dashboard access to trusted users only.
  • Regular Audits: Conduct periodic security audits of your WordPress plugins and themes.

Get AI-powered remediation steps tailored to your asset.

Try AI Solutions →

Check your infrastructure.
Right now.

11,000+ scanners. Free to start. No credit card required.