#VU125513 Insufficient verification of data authenticity in AVideo - CVE-2026-39366
Published: April 8, 2026
AVideo
World Wide Broadcast Network
Description
The vulnerability allows a remote user to inflate wallet balances and renew subscriptions without additional payment.
The vulnerability exists due to insufficient verification of data authenticity in the PayPal IPN v1 handler in plugin/PayPalYPT/ipn.php when processing replayed legitimate IPN notifications. A remote user can replay a previously captured valid IPN request to inflate wallet balances and renew subscriptions without additional payment.
Exploitation requires a legitimate prior PayPal subscription payment and access to the corresponding IPN POST data.