CVE Explorer
CVE-2026-34737
WWBN AVideo is an open source video platform. In versions 26.0 and prior, the StripeYPT plugin includes a test.php debug endpoint that is accessible to any logged-in user, not just administrators. This endpoint processes Stripe webhook-style payloads and triggers subscription operations, including cancellation. Due to a bug in the retrieveSubscriptions() method that cancels subscriptions instead of merely retrieving them, any authenticated user can cancel arbitrary Stripe subscriptions by provid
Known exploited
Not asserted
Disputed
No
Stale source
No
Conflicts
0
Affected products and versions
1 source assertion{"product":"AVideo","vendor":"WWBN","versions":[{"status":"affected","version":"<= 26.0"}]}
- cve_program_cvelist_v5affectedurn:baitaphish:normalized-source-record:v2:69dd3666c28c4fd1f413fefdc08695dc0dcf60cc4a466c36186950cfafe816ce · sha256:78a4f428fff97e7e… · /containers/cna/affected/0
Provider-owned CVSS observations
1 source assertion{"metric":{"attackComplexity":"LOW","attackVector":"NETWORK","availabilityImpact":"NONE","baseScore":6.5,"baseSeverity":"MEDIUM","confidentialityImpact":"NONE","integrityImpact":"HIGH","privilegesRequired":"LOW","scope":"UNCHANGED","userInteraction":"NONE","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N","version":"3.1"},"metric_type":"cvssV3_1"}
- cve_program_cvelist_v5cvssurn:baitaphish:normalized-source-record:v2:69dd3666c28c4fd1f413fefdc08695dc0dcf60cc4a466c36186950cfafe816ce · sha256:78a4f428fff97e7e… · /containers/cna/metrics/0/cvssV3_1
CWE assertions
1 source assertion{"cweId":"CWE-862","description":"CWE-862: Missing Authorization","lang":"en","type":"CWE"}
- cve_program_cvelist_v5cweurn:baitaphish:normalized-source-record:v2:69dd3666c28c4fd1f413fefdc08695dc0dcf60cc4a466c36186950cfafe816ce · sha256:78a4f428fff97e7e… · /containers/cna/problemTypes/0/descriptions/0
Source references
1 source assertion{"name":"https://github.com/WWBN/AVideo/security/advisories/GHSA-38rh-4v39-vfxv","tags":["x_refsource_CONFIRM"],"url":"https://github.com/WWBN/AVideo/security/advisories/GHSA-38rh-4v39-vfxv"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:69dd3666c28c4fd1f413fefdc08695dc0dcf60cc4a466c36186950cfafe816ce · sha256:78a4f428fff97e7e… · /containers/cna/references/0
Attribution and limitations
- CVE Program CVEList V5: Reproduce the MITRE copyright designation and CVE license in copies. Source →
Provider severity values are preserved separately. Baitaphish does not convert them into a risk rating, infer affected products, or treat EPSS as observed exploitation.