CVE-2025-15516 | All-in-One Video Gallery Plugin up to 4.1.0/4.6.4 on WordPress User Meta Update ajax_callback_store_user_meta authorization (EUVD-2026-4550)
A vulnerability categorized as problematic has been discovered in All-in-One Video Gallery Plugin up to 4.1.0/4.6.4 on WordPress. Affected by this issue is the function ajax_callback_store_user_meta of the component User Meta Update Handler. Such manipulation leads to missing authorization.
This vulnerability is listed as CVE-2025-15516. The attack may be performed from remote. There is no available exploit.