Impact
The vulnerability in WWBN AVideo allows an attacker to perform unlimited password guesses against any user account through the undocumented get_api_preauthorize endpoint. The endpoint omits rate limiting, checks credentials the same way as the official sign‑in route, and returns a generic "Invalid credentials" message for both correct and incorrect passwords. However, the response includes the authenticated identity via a users_id field (users_id:1 for success, users_id:0 for failure) and, on a successful credential match, establishes a session cookie usable for subsequent authenticated API calls. This combination permits passive credential enumeration followed by active account takeover without any special privileges or local access.
Affected Systems
Any installation of the WWBN AVideo plugin where plugin/API/API.php exposes the get_api_preauthorize endpoint, including the commit e01e41ecc. No patched version is currently available, so all current releases remain vulnerable.
Risk and Exploitability
With a CVSS score of 9.1, the vulnerability is classified as critical. No EPSS data is available, and the vulnerability is not listed in CISA's KEV catalog, but the absence of throttling and the ability to gain legitimate session cookies from successful guesses make exploitation highly feasible for remote attackers. The attack vector is remote and does not require any privileged credentials; an adversary only needs network access to the API endpoint.
OpenCVE Enrichment