Indicator
Type cve · source NVD CVE
Enrichment by provider
Grouped attempts with latest status; expand for attempt history.
2 attempts · first 2026-07-21T12:20:10.898558Z · last 2026-07-21T13:50:45.061208Z
Not listed in CISA KEV (local)
Types: cisa_kev
2 attempts · first 2026-07-21T12:20:10.884558Z · last 2026-07-21T13:50:45.048387Z
EPSS=0.00246
Types: epss
2 attempts · first 2026-07-21T12:20:10.904042Z · last 2026-07-21T13:50:45.065927Z
The All-in-One Video Gallery plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 4.8.5 via the 'vdl' parameter. This makes it possible for authenticated attackers, with subscriber-level access and above, to make web requests to arbitrary locations originating from the web application and can be used to query and modify information from internal s
Types: nvd_local
CONTINUE INVESTIGATION
High-signal pivots without leaving the thread you started in search.
Structured pivots from local graph context.
See edges, pivots, and corroboration at a glance.
Full inspector with neighbor expansion.