Authentication Bypass in WWBN AVideo Bookmark Plugin
CVE-2026-90547
6.9MEDIUM
What is CVE-2026-90547?
The WWBN AVideo Bookmark plugin has a security flaw in the getBookmarks.json.php endpoint due to inadequate user permissions validation. This vulnerability allows unauthorized attackers to access and read chapter names from videos that are intended to be password-protected. By simply querying the endpoint with a valid video ID, attackers can retrieve sensitive chapter metadata without requiring any form of authentication or password verification, posing a significant risk to user privacy and content security.
Affected Version(s)
AVideo 0
