Authorization Flaw in WWBN AVideo Affects PayPal Billing Agreement Management
CVE-2026-43883

4.2MEDIUM

Key Information:

Vendor

Wwbn

Status
Vendor
CVE Published:
11 May 2026

What is CVE-2026-43883?

An authorization flaw exists in WWBN AVideo, an open-source video platform. In versions up to and including 29.0, the functionality for canceling PayPal billing agreements does not properly verify ownership of the agreement by the authenticated user. This allows a low-privilege user, who has maliciously acquired another user's PayPal billing agreement ID, to silently cancel the victim's recurring subscription. This vulnerability can lead to financial losses for service providers and disrupt service for affected users. For further details, a fix has been implemented in commit 0da3dcff1eda2f497694bf82b559829471c292c2.

Affected Version(s)

AVideo <= 29.0

References

CVSS V3.1

Score:
4.2
Severity:
MEDIUM
Confidentiality:
None
Integrity:
Low
Availability:
None
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.