Authorization Flaw in WWBN AVideo Affects PayPal Billing Agreement Management
CVE-2026-43883
4.2MEDIUM
What is CVE-2026-43883?
An authorization flaw exists in WWBN AVideo, an open-source video platform. In versions up to and including 29.0, the functionality for canceling PayPal billing agreements does not properly verify ownership of the agreement by the authenticated user. This allows a low-privilege user, who has maliciously acquired another user's PayPal billing agreement ID, to silently cancel the victim's recurring subscription. This vulnerability can lead to financial losses for service providers and disrupt service for affected users. For further details, a fix has been implemented in commit 0da3dcff1eda2f497694bf82b559829471c292c2.
Affected Version(s)
AVideo <= 29.0
