Authentication Bypass in WWBN AVideo Bookmark Plugin
CVE-2026-90547

6.9MEDIUM

Key Information:

Vendor

Wwbn

Status
Vendor
CVE Published:
12 September 2026

What is CVE-2026-90547?

The WWBN AVideo Bookmark plugin has a security flaw in the getBookmarks.json.php endpoint due to inadequate user permissions validation. This vulnerability allows unauthorized attackers to access and read chapter names from videos that are intended to be password-protected. By simply querying the endpoint with a valid video ID, attackers can retrieve sensitive chapter metadata without requiring any form of authentication or password verification, posing a significant risk to user privacy and content security.

Affected Version(s)

AVideo 0

References

CVSS V4

Score:
6.9
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

santhreal
.