Description
In AVideo through 29.0, the autoCSRFGuard() function maintains a hardcoded allowlist of exempt basenames tested without directory context, allowing plugin files matching core filenames to inherit CSRF exemptions. The LoginWordPress plugin file login.json.php inherits an exemption and unconditionally logs out authenticated users on cross-site POST requests before validating credentials.
Published: 2026-09-16
Score: 5.3 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Denial of Service (Forced Logout)
Action: Assess Impact
AI Analysis

Impact

In the affected AVideo releases up to 29.0, the autoCSRFGuard function contains a hard‑coded allowlist of exempt basenames, causing any plugin file that matches a core file to inherit a CSRF exemption. The LoginWordPress plugin provides a file named login.json.php, which, because of this basename collision, is exempt from CSRF checks. When a cross‑site POST request targets that file, the plugin logs out the current authenticated user before performing any credential validation. The flaw therefore enables an attacker to force users to lose their session, causing a denial of service for authenticated access. The weakness is classified as CWE‑289 Broken Access Control.

Affected Systems

Vulnerable installations are any users running WWBN’s AVideo product version 29.0 or earlier. No specific patch versions are listed, so all releases through 29.0 are affected.

Risk and Exploitability

The CVSS score of 5.3 places the vulnerability in the moderate range. The EPSS score is below 1 %, indicating that exploit attempts are expected to be rare. The vulnerability is not listed in CISA’s KEV catalog. Attackers can exploit the flaw by simply crafting a cross‑site POST request to the LoginWordPress plugin’s login.json.php endpoint, which requires no authentication and relies solely on the CSRF exemption held by the basename collision. The impact is limited to session termination, so the overall risk is moderate but with low exploitation likelihood.

Generated by OpenCVE AI on September 18, 2026 at 05:25 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade AVideo to a version newer than 29.0 that resolves the CSRF exemption issue.
  • If an upgrade is not immediately feasible, disable or remove the LoginWordPress plugin to eliminate the vulnerable endpoint.
  • Add a CSRF token check to the login.json.php file or wrap the endpoint with generic CSRF protection to prevent unauthorized POST requests.
  • Configure the web server or application firewall to block or challenge cross‑site POST traffic to login.json.php until the vulnerability is fixed.

Generated by OpenCVE AI on September 18, 2026 at 05:25 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 18 Sep 2026 21:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Fri, 18 Sep 2026 10:45:00 +0000

Type Values Removed Values Added
First Time appeared Wordpress
Wordpress wordpress
Vendors & Products Wordpress
Wordpress wordpress

Wed, 16 Sep 2026 22:00:00 +0000

Type Values Removed Values Added
Description In AVideo through 29.0, the autoCSRFGuard() function maintains a hardcoded allowlist of exempt basenames tested without directory context, allowing plugin files matching core filenames to inherit CSRF exemptions. The LoginWordPress plugin file login.json.php inherits an exemption and unconditionally logs out authenticated users on cross-site POST requests before validating credentials.
Title AVideo through 29.0 Broken Access Control via CSRF Exemption Basename Collision
First Time appeared Wwbn
Wwbn avideo
Weaknesses CWE-289
CPEs cpe:2.3:a:wwbn:avideo:*:*:*:*:*:*:*:*
Vendors & Products Wwbn
Wwbn avideo
References
Metrics cvssV3_1

{'score': 5.4, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:L'}

cvssV4_0

{'score': 5.3, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:N/VI:L/VA:L/SC:N/SI:N/SA:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: VulnCheck

Published:

Updated: 2026-09-18T20:13:56.256Z

Reserved: 2026-09-16T13:47:20.117Z

Link: CVE-2026-92579

cve-icon Vulnrichment

Updated: 2026-09-18T20:13:04.386Z

cve-icon NVD

Status : Deferred

Published: 2026-09-16T22:18:28.193

Modified: 2026-09-22T20:43:58.793

Link: CVE-2026-92579

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-18T10:30:07Z

Weaknesses
  • CWE-289

    Authentication Bypass by Alternate Name