Missing Authorization Issue in WWBN AVideo Scheduler Plugin
CVE-2026-90537

8.8HIGH

Key Information:

Vendor

Wwbn

Status
Vendor
CVE Published:
12 September 2026

What is CVE-2026-90537?

The WWBN AVideo Scheduler plugin contains a vulnerability due to missing authorization in the sendEmail.json.php file. This flaw enables unauthenticated attackers to exploit a site-wide daily token, gaining unauthorized access to sensitive scheduler email jobs. Attackers can enumerate the scheduler jobs, access private live titles and email addresses, and trigger email notifications by submitting valid daily tokens obtained from public Live pages. This creates a significant risk to user privacy and data security.

Affected Version(s)

AVideo 0

References

CVSS V4

Score:
8.8
Severity:
HIGH
Confidentiality:
High
Integrity:
Low
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

santhreal
.