
CVE-2026-1706 The All-in-One Video Gallery plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'vi' parameter in all versions up to, and including, 4.7.1 due… https://www.cve.org/CVERecord?id=CVE-2026-1706
Post summary
The All‑in‑One Video Gallery WordPress plugin (v4.7.1 and earlier) is susceptible to a reflected XSS via the 'vi' parameter, with no PoC, exploit, or patch information provided.



