Stored Cross-Site Scripting in AVideo's YPTWallet Plugin
CVE-2026-89249

9.3CRITICAL

Key Information:

Vendor

Wwbn

Status
Vendor
CVE Published:
11 September 2026

What is CVE-2026-89249?

AVideo's YPTWallet plugin is prone to a stored cross-site scripting vulnerability where user-defined CryptoWallet values are improperly handled. These values are base64-encoded but lack HTML-escaping before being stored in the wallet_log.information. As a result, when administrators review pending withdrawal requests, they inadvertently execute the stored malicious markup within their session. This flaw can be exploited by attackers to execute administrative actions through same-origin fetch requests, posing significant risks to the application's integrity and user security.

Affected Version(s)

AVideo 0

References

CVSS V4

Score:
9.3
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
Unknown

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

santhreal
.