Missing Authorization in AVideo - #VU125488
Published: April 8, 2026
AVideo
Detailed vulnerability description
The vulnerability allows a remote attacker to disclose sensitive financial and transaction information.
The vulnerability exists due to missing authorization in payment plugin list.json.php endpoints when handling unauthenticated HTTP requests. A remote attacker can send a specially crafted request to disclose sensitive financial and transaction information.
A single GET request can return PayPal billing agreement IDs, Express Checkout tokens, Authorize.Net webhook payloads, Bitcoin payment records, payment amounts, and user-linked transaction data.