6.5
/ 10
MEDIUM
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L
Description
The All-in-One Video Gallery plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the `ajax_callback_create_bunny_stream_video`, `ajax_callback_get_bunny_stream_video`, and `ajax_callback_delete_bunny_stream_video` functions in all versions up to, and including, 4.6.4. This makes it possible for unauthenticated attackers to create and delete videos on the Bunny Stream CDN associated with the victim's account, provided they can obtain a valid nonce which is exposed in public player templates.
Basic Information
ID
CVE-2025-14947
Source
Wordfence
Published
Jan 23, 2026 at 17:26
Modified
Jan 23, 2026 at 18:20
Affected Product
Vendor
plugins360
Product
All-in-One Video Gallery
Version
*
Affected Versions
plugins360 All-in-One Video Gallery *
CWE Classification
References
- www.wordfence.com /threat-intel/vulnerabilities/id/bedfb712-faf6-4131-b254-e6d7c367f49f
- plugins.trac.wordpress.org /browser/all-in-one-video-gallery/trunk/includes/init.php
- plugins.trac.wordpress.org /browser/all-in-one-video-gallery/trunk/public/bunny-stream.php
- plugins.trac.wordpress.org /browser/all-in-one-video-gallery/trunk/public/bunny-stream.php
- plugins.trac.wordpress.org /changeset/3441541/