CVE-2026-34737
published 2026-03-31CVE-2026-34737: WWBN AVideo is an open source video platform. In versions 26.0 and prior, the StripeYPT plugin includes a test.php debug endpoint that is accessible to any…
PriorityP340medium6.5CVSS 3.1
AVNACLPRLUINSUCNIHAN
EPSS
0.28%
20.8th percentile
WWBN AVideo is an open source video platform. In versions 26.0 and prior, the StripeYPT plugin includes a test.php debug endpoint that is accessible to any logged-in user, not just administrators. This endpoint processes Stripe webhook-style payloads and triggers subscription operations, including cancellation. Due to a bug in the retrieveSubscriptions() method that cancels subscriptions instead of merely retrieving them, any authenticated user can cancel arbitrary Stripe subscriptions by providing a subscription ID. At time of publication, there are no publicly available patches.
Affected
2 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| wwbn | avideo | <= 26.0 | — |
| wwbn | avideo | 0 – 26.0 | — |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
VulDB
WWBN AVideo up to 26.0 Endpoint test.php retrieveSubscriptions authorization (GHSA-38rh-4v39-vfxv)
vuldb·2026-07-26·CVSS 6.5
CVE-2026-34737 [MEDIUM] WWBN AVideo up to 26.0 Endpoint test.php retrieveSubscriptions authorization (GHSA-38rh-4v39-vfxv)
A vulnerability was found in WWBN AVideo up to 26.0. It has been declared as problematic. Affected by this issue is the function retrieveSubscriptions of the file test.php of the component Endpoint. Such manipulation leads to missing authorization.
This vulnerability is uniquely identified as CVE-2026-34737. The attack can be launched remotely. No exploit exists.
GHSA
AVideo: Arbitrary Stripe Subscription Cancellation via Debug Endpoint and retrieveSubscriptions() Bug
ghsa·2026-04-01
CVE-2026-34737 [MEDIUM] CWE-862 AVideo: Arbitrary Stripe Subscription Cancellation via Debug Endpoint and retrieveSubscriptions() Bug
AVideo: Arbitrary Stripe Subscription Cancellation via Debug Endpoint and retrieveSubscriptions() Bug
## Summary
The StripeYPT plugin includes a `test.php` debug endpoint that is accessible to any logged-in user, not just administrators. This endpoint processes Stripe webhook-style payloads and triggers subscription operations, including cancellation. Due to a bug in the `retrieveSubscriptions()` method that cancels subscriptions instead of merely retrieving them, any authenticated user can cancel arbitrary Stripe subscriptions by providing a subscription ID.
## Details
At `plugin/StripeYPT/test.php:4`, the endpoint checks only for a logged-in user, not for admin privileges:
```php
if (!User::isLogged())
```
At lines 27-29, the endpoint accepts a JSON payload from the request and pro
OSV
AVideo: Arbitrary Stripe Subscription Cancellation via Debug Endpoint and retrieveSubscriptions() Bug
osv·2026-04-01
CVE-2026-34737 [MEDIUM] AVideo: Arbitrary Stripe Subscription Cancellation via Debug Endpoint and retrieveSubscriptions() Bug
AVideo: Arbitrary Stripe Subscription Cancellation via Debug Endpoint and retrieveSubscriptions() Bug
## Summary
The StripeYPT plugin includes a `test.php` debug endpoint that is accessible to any logged-in user, not just administrators. This endpoint processes Stripe webhook-style payloads and triggers subscription operations, including cancellation. Due to a bug in the `retrieveSubscriptions()` method that cancels subscriptions instead of merely retrieving them, any authenticated user can cancel arbitrary Stripe subscriptions by providing a subscription ID.
## Details
At `plugin/StripeYPT/test.php:4`, the endpoint checks only for a logged-in user, not for admin privileges:
```php
if (!User::isLogged())
```
At lines 27-29, the endpoint accepts a JSON payload from the request and pro
No detection rules found.
No public exploits indexed.
2026-03-31
Published