#VU125488 Missing Authorization in AVideo
Published: April 8, 2026
AVideo
World Wide Broadcast Network
Description
The vulnerability allows a remote attacker to disclose sensitive financial and transaction information.
The vulnerability exists due to missing authorization in payment plugin list.json.php endpoints when handling unauthenticated HTTP requests. A remote attacker can send a specially crafted request to disclose sensitive financial and transaction information.
A single GET request can return PayPal billing agreement IDs, Express Checkout tokens, Authorize.Net webhook payloads, Bitcoin payment records, payment amounts, and user-linked transaction data.