← back
CVE-2026-35448

WWBN AVideo Provides Unauthenticated Access to Payment Order Data via BlockonomicsYPT check.php

CVSS 3.7 LOWEPSS 0.3%CWE-862
Vexday Risk Score
8Low
SSVC decision (CISA)
Track
No exploitation signal → monitor
CVSS 3.7EPSS 0.3%KEV nãoPoC Nuclei Metasploit Patch
Lifecycle
06 Apr 2026Published on NVD
Recommendation: Monitor — no exploitation signal at the moment.
WWBN AVideo is an open source video platform. In versions 26.0 and prior, the BlockonomicsYPT plugin's check.php endpoint returns payment order data for any Bitcoin address without requiring authentication. The endpoint was designed as an AJAX polling helper for the authenticated invoice.php page, but it performs no access control checks of its own. Since Bitcoin addresses are publicly visible on the blockchain, an attacker can query payment records for any address used on the platform.
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N
Affected products
WWBN · AVideo

Want to know if your infrastructure is exposed to this?

Talk to TrueHacking →