Missing Authorization Issue in WWBN AVideo Scheduler Plugin
CVE-2026-90537
8.8HIGH
What is CVE-2026-90537?
The WWBN AVideo Scheduler plugin contains a vulnerability due to missing authorization in the sendEmail.json.php file. This flaw enables unauthenticated attackers to exploit a site-wide daily token, gaining unauthorized access to sensitive scheduler email jobs. Attackers can enumerate the scheduler jobs, access private live titles and email addresses, and trigger email notifications by submitting valid daily tokens obtained from public Live pages. This creates a significant risk to user privacy and data security.
Affected Version(s)
AVideo 0
