CVE-2026-33731
published 2026-07-16CVE-2026-33731: WWBN AVideo is an open source video platform. In versions prior to 29.0, the Authorize.Net webhook handler at plugin/AuthorizeNet/webhook.php contains a…
PriorityP341medium6.5CVSS 3.1
AVNACLPRLUINSUCNIHAN
EPSS
0.14%
4.1th percentile
WWBN AVideo is an open source video platform. In versions prior to 29.0, the Authorize.Net webhook handler at plugin/AuthorizeNet/webhook.php contains a signature verification bypass that allows an attacker to forge webhook requests with arbitrary payment amounts and target user IDs. By supplying a valid transaction ID from a small legitimate purchase, the attacker bypasses signature validation and credits arbitrary wallet balances to any user account via attacker-controlled payload fields. Three flaws combine into an exploit chain: signature bypass via OR logic (webhook.php:33), payload values override API-fetched values (AuthorizeNet.php:169-171, webhook.php:44-48) and a missing approval check (webhook.php:61-75). By forging payment metadata, an attacker can credit arbitrary amounts to any user's wallet without a corresponding payment and include a plans_id to activate premium subscriptions (webhook.php:86-134), enabling free access to all paid and premium content and causing direct revenue loss to the platform owner. This issue has been fixed in version 29.0.
Affected
2 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| wwbn | avideo | < 29.0 | 29.0 |
| wwbn | avideo | >= 0 < 29.0 | 29.0 |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
VulDB
WWBN AVideo up to 28.x Webhook webhook.php plans_id signature verification
vuldb·2026-07-16·CVSS 6.5
CVE-2026-33731 [MEDIUM] WWBN AVideo up to 28.x Webhook webhook.php plans_id signature verification
A vulnerability identified as critical has been detected in WWBN AVideo up to 28.x. This issue affects some unknown processing of the file plugin/AuthorizeNet/webhook.php of the component Webhook Handler. Performing a manipulation of the argument plans_id results in improper verification of cryptographic signature.
This vulnerability is reported as CVE-2026-33731. The attack is possible to be carried out remotely. No exploit exists.
GHSA
AVideo has an Authorize.Net Webhook Signature Bypass that Enables Wallet Balance Inflation via Forged Payment Data
ghsa·2026-06-22
CVE-2026-33731 [MEDIUM] CWE-345 AVideo has an Authorize.Net Webhook Signature Bypass that Enables Wallet Balance Inflation via Forged Payment Data
AVideo has an Authorize.Net Webhook Signature Bypass that Enables Wallet Balance Inflation via Forged Payment Data
## Summary
The Authorize.Net webhook handler at `plugin/AuthorizeNet/webhook.php` contains a signature verification bypass that allows an attacker to forge webhook requests with arbitrary payment amounts and target user IDs. By supplying a valid transaction ID from a small legitimate purchase, the attacker bypasses signature validation and credits arbitrary wallet balances to any user account via attacker-controlled payload fields.
## Details
Three flaws combine into an exploit chain:
### 1. Signature Bypass via OR Logic (webhook.php:33)
```php
if (!$parsed['signatureValid'] && (empty($txnInfo) || !empty($txnInfo['error']))) {
http_response_code(401);
echo 'invalid signa
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2026-07-16
Published