CVE-2026-86724: Wwbn Avideo
Medium severity, CVSS 6.5. EPSS: 0.2% chance of exploitation in the next 30 days.
AVideo through commit c3edcc274c389816d434acadac07ee78eaf330c1 contains a cross-site request forgery vulnerability in plugin/YPTWallet/view/saveBalance.php that allows attackers to set arbitrary wallet balances by relying only on session cookies without token validation. Attackers can craft a malicious webpage that, when loaded by an administrator, submits a POST request to modify any user's wallet balance to any value.
Affected products
- Wwbn Avideo
Published 2026-09-08. Last modified 2026-09-10.