GHSA-wprj-9cvc-5w37: AVideo: Unauthenticated Access to Payment Log DataTables Endpoints Exposes Transaction Data, PayPal Tokens, and User Financial Records
highvulnerability
security
Source: GitHub Advisory DatabaseMarch 29, 2026
Summary
AVideo's payment plugins have a critical vulnerability where `list.json.php` endpoints (which retrieve payment transaction records) lack authentication checks, allowing anyone to access sensitive financial data including PayPal tokens, Authorize.Net webhook details, Bitcoin transaction records, and user IDs without logging in. This is the same type of vulnerability that was previously fixed in the Scheduler plugin, but the fix was not applied to 21 other vulnerable endpoints across the codebase.
Classification
Attack SophisticationTrivial
Affected Packages
wwbn/avideo@<= 26.0
Monthly digest — independent AI security research
Original source: https://github.com/advisories/GHSA-wprj-9cvc-5w37
First tracked: March 29, 2026 at 02:00 PM
Classified by LLM (prompt v3) · confidence: 95%