Exploitation Summary
EIP tracks 1 public exploit for CVE-2012-6653. PoCs published by Ashiyane Digital Security Team.
AI-analyzed exploit summary This exploit demonstrates a SQL injection vulnerability in WordPress All Video Gallery plugin version 1.1. The PoC uses a UNION-based SQLi to extract user credentials from the wp_users table.
Description
Unspecified vulnerability in the All Video Gallery (all-video-gallery) plugin before 1.2.0 for WordPress has unspecified impact and attack vectors.
Exploits (1)
exploitdb
WORKING POC
VERIFIED
by Ashiyane Digital Security Team · textwebappsphp
https://www.exploit-db.com/exploits/22427
This exploit demonstrates a SQL injection vulnerability in WordPress All Video Gallery plugin version 1.1. The PoC uses a UNION-based SQLi to extract user credentials from the wp_users table.
Classification
Working Poc 90%
Attack Type
Sqli
Complexity
Trivial
Reliability
Reliable
Target:
WordPress All Video Gallery 1.1
No auth needed
Prerequisites:
WordPress All Video Gallery plugin version 1.1 installed · Access to the config.php endpoint
devstral-2 · analyzed Feb 16, 2026
Full analysis →
References (1)
Core 1
Core References
Patch x_refsource_confirm
http://wordpress.org/plugins/all-video-gallery/changelog/
Scores
EPSS
0.0668
EPSS Percentile
93.0%
Details
Status
published
Products (2)
all_video_gallery_plugin_project/all_video_gallery_plugin
1.0.0
all_video_gallery_plugin_project/all_video_gallery_plugin
< 1.1.0
Published
Aug 06, 2014
Tracked Since
Feb 18, 2026