Stored Cross-Site Scripting in AVideo's YPTWallet Plugin
CVE-2026-89249
9.3CRITICAL
What is CVE-2026-89249?
AVideo's YPTWallet plugin is prone to a stored cross-site scripting vulnerability where user-defined CryptoWallet values are improperly handled. These values are base64-encoded but lack HTML-escaping before being stored in the wallet_log.information. As a result, when administrators review pending withdrawal requests, they inadvertently execute the stored malicious markup within their session. This flaw can be exploited by attackers to execute administrative actions through same-origin fetch requests, posing significant risks to the application's integrity and user security.
Affected Version(s)
AVideo 0
