Junglewise Threat Intelligence

CVE-2026-34395: WWBN AVideo missing authorization in YPTWallet users endpoint

CVE-2026-34395 · Severity: medium · CVSS 6.5 · Published 2026-03-31

Technologies: wwbn/avideo (Packagist), WWBN AVideo. Vendors: Packagist, WWBN.

Executive brief

WWBN AVideo is an open-source platform used for hosting and sharing video content. A security flaw in the platform's wallet plugin allows any registered user to download the entire database of other users, including sensitive personal information and financial balances. This exposure includes names, email addresses, phone numbers, and physical addresses, which could lead to significant privacy breaches and regulatory compliance issues.

Technical details

A missing authorization check exists in the YPTWallet plugin of WWBN AVideo versions 26.0 and earlier. Specifically, the 'users.json.php' endpoint validates that a user is logged in using 'User::isLogged()' but fails to verify administrative privileges via 'User::isAdmin()'. An authenticated attacker with low-level privileges can query this endpoint to receive a JSON response containing the full 'users' and 'wallet' table data. Exposed Personally Identifiable Information (PII) includes email addresses, phone numbers, physical addresses, birth dates, and wallet balances. While passwords are filtered, the remaining data constitutes a significant mass disclosure. No official patch was available at the time of the advisory.

Affected products

  • WWBN AVideo <= 26.0

Timeline

  • 2026-03-27: advisory: Original GitHub security advisory published
  • 2026-03-31: disclosed: CVE-2026-34395 published to NVD

References

Related threats