Description

The All-in-One Video Gallery plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the ajax_callback_store_user_meta() function in versions 4.1.0 to 4.6.4. This makes it possible for authenticated attackers, with Subscriber-level access and above, to update arbitrary string-based user meta keys for their own account.

INFO

Published Date :

2026-01-24T08:26:33.155Z

Last Modified :

2026-01-26T18:05:35.718Z

Source :

Wordfence
AFFECTED PRODUCTS

The following products are affected by CVE-2025-15516 vulnerability.

Vendors Products
Plugins360
  • All-in-one Video Gallery
Wordpress
  • Wordpress

CVSS Vulnerability Scoring System

Detailed values of each vector for above chart.
Attack Vector
Attack Complexity
Privileges Required
User Interaction
Scope
Confidentiality Impact
Integrity Impact
Availability Impact