Unauthenticated Information Disclosure in WWBN AVideo Plugin
CVE-2026-90541
6.9MEDIUM
What is CVE-2026-90541?
The WWBN AVideo plugin has a security issue where the plugin/TopMenu/menus.json.php endpoint does not require user authentication, allowing unauthenticated attackers to access sensitive menu information. This vulnerability enables attackers to perform GET requests, retrieving inactive and admin-only menu names that are hidden from the public interface. This could lead to potential exploitation or insight into the administrative structure and settings of the application.
Affected Version(s)
AVideo 0
