Authorization Bypass in WWBN AVideo Affects User Wallet Balance
CVE-2026-47696

7.1HIGH

Key Information:

Vendor

Wwbn

Status
Vendor
CVE Published:
29 May 2026

What is CVE-2026-47696?

WWBN AVideo, an open-source video platform, has a vulnerability in its payment processing functionality. In versions up to 29.0, an attacker can exploit the 'processPayment.json.php' endpoint to manipulate the wallet balance of any logged-in user. This occurs because the system accepts an attacker-controlled 'amount' parameter without validation against Authorize.Net transactions, webhook signatures, or transaction records. As a result, users can arbitrarily increase their wallet balance, posing significant security risks if the required plugins are enabled.

Affected Version(s)

AVideo <= 29.0

References

CVSS V4

Score:
7.1
Severity:
HIGH
Confidentiality:
None
Integrity:
High
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.