Data Exposure in AVideo by WWBN Affects User Personal Information
CVE-2026-34395
6.5MEDIUM
What is CVE-2026-34395?
The AVideo platform from WWBN possesses a significant vulnerability affecting the plugin's endpoint that retrieves user information. The endpoint at /YPTWallet/view/users.json.php is accessible to all authenticated users, allowing them to view sensitive personal details and wallet balances of all registered users. The vulnerability arises since the system only checks if a user is logged in, neglecting to verify administrative privileges. This oversight permits unauthorized data access, which can lead to severe privacy breaches. At present, there are no patches available to address this issue.
Affected Version(s)
AVideo <= 26.0
