Missing Authorization in AVideo - CVE-2026-56341
Published: May 4, 2026 / Updated: September 14, 2026
Vulnerability details
The vulnerability allows a remote attacker to disclose sensitive information.
The vulnerability exists due to missing authorization in payment plugin list.json.php endpoints when handling unauthenticated requests for payment log data. A remote attacker can send a specially crafted request to disclose sensitive information.
The exposed records include PayPal billing agreement IDs, Express Checkout tokens, Authorize.Net webhook payloads, Bitcoin payment records, user identifiers, and payment amounts.