Cross-Site Request Forgery Vulnerability in AVideo by WWBN
CVE-2026-92579

5.3MEDIUM

Key Information:

Vendor

WordPress

Status
Vendor
CVE Published:
16 September 2026

What is CVE-2026-92579?

The AVideo platform, versions up to 29.0, contains a serious vulnerability in its autoCSRFGuard() function. This function maintains a hardcoded allowlist that bypasses necessary directory context checks. As a result, certain plugin files, including the one used by the LoginWordPress plugin (login.json.php), are improperly exempted from CSRF protections. This exemption can allow an attacker to unconditionally log out authenticated users through cross-site POST requests before proper credential validation occurs, potentially leading to unauthorized disruptions and degraded user experience.

Affected Version(s)

AVideo 0 <= 29.0

References

CVSS V4

Score:
5.3
Severity:
MEDIUM
Confidentiality:
None
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
Unknown

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

rajivraj
.