PT-2026-29364 · WordPress+1 · Stripeypt+1

·

CVE-2026-34737

·

Publicado

2026-03-31

·

Atualizado

2026-07-24

CVSS v3.1

6.5

Média

VetorAV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N
Name of the Vulnerable Software and Affected Versions AVideo versions 26.0 and prior
Description AVideo is an open source video platform. A debug endpoint, test.php, within the StripeYPT plugin is accessible to all logged-in users, not just administrators. This endpoint processes Stripe webhook-style payloads and triggers subscription operations, including cancellation. A flaw in the retrieveSubscriptions() method causes subscriptions to be cancelled instead of retrieved. This allows any authenticated user to cancel arbitrary Stripe subscriptions by providing a subscription ID.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Missing Authorization

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2026-34737
GHSA-38RH-4V39-VFXV

Produtos afetados

Avideo
Stripeypt