Authorization Bypass in WWBN AVideo Affects User Wallet Balance
CVE-2026-47696
7.1HIGH
What is CVE-2026-47696?
WWBN AVideo, an open-source video platform, has a vulnerability in its payment processing functionality. In versions up to 29.0, an attacker can exploit the 'processPayment.json.php' endpoint to manipulate the wallet balance of any logged-in user. This occurs because the system accepts an attacker-controlled 'amount' parameter without validation against Authorize.Net transactions, webhook signatures, or transaction records. As a result, users can arbitrarily increase their wallet balance, posing significant security risks if the required plugins are enabled.
Affected Version(s)
AVideo <= 29.0
