Impact
In the affected AVideo releases up to 29.0, the autoCSRFGuard function contains a hard‑coded allowlist of exempt basenames, causing any plugin file that matches a core file to inherit a CSRF exemption. The LoginWordPress plugin provides a file named login.json.php, which, because of this basename collision, is exempt from CSRF checks. When a cross‑site POST request targets that file, the plugin logs out the current authenticated user before performing any credential validation. The flaw therefore enables an attacker to force users to lose their session, causing a denial of service for authenticated access. The weakness is classified as CWE‑289 Broken Access Control.
Affected Systems
Vulnerable installations are any users running WWBN’s AVideo product version 29.0 or earlier. No specific patch versions are listed, so all releases through 29.0 are affected.
Risk and Exploitability
The CVSS score of 5.3 places the vulnerability in the moderate range. The EPSS score is below 1 %, indicating that exploit attempts are expected to be rare. The vulnerability is not listed in CISA’s KEV catalog. Attackers can exploit the flaw by simply crafting a cross‑site POST request to the LoginWordPress plugin’s login.json.php endpoint, which requires no authentication and relies solely on the CSRF exemption held by the basename collision. The impact is limited to session termination, so the overall risk is moderate but with low exploitation likelihood.
OpenCVE Enrichment