Cross-Site Request Forgery Vulnerability in AVideo by WWBN
CVE-2026-92579
5.3MEDIUM
What is CVE-2026-92579?
The AVideo platform, versions up to 29.0, contains a serious vulnerability in its autoCSRFGuard() function. This function maintains a hardcoded allowlist that bypasses necessary directory context checks. As a result, certain plugin files, including the one used by the LoginWordPress plugin (login.json.php), are improperly exempted from CSRF protections. This exemption can allow an attacker to unconditionally log out authenticated users through cross-site POST requests before proper credential validation occurs, potentially leading to unauthorized disruptions and degraded user experience.
Affected Version(s)
AVideo 0 <= 29.0