关键漏洞信息 Vulnerability: Missing Authorization to Unauthenticated Bunny Stream Video Creation/Deletion CVE ID: CVE-2025-14947 CVSS Score: 6.5 (Medium) Published Date: January 22, 2026 Last Updated: January 23, 2026 Researcher: andrea bocchetti Software Type: Plugin Software Slug: all-in-one-video-gallery Patched?: Yes Remediation: Update to version 4.7.1, or a newer patched version Affected Version: <= 4.6.4 Patched Version: 4.7.1 References: - plugins.trac.wordpress.org - plugins.trac.wordpress.org - plugins.trac.wordpress.org - plugins.trac.wordpress.org