PT-2026-51434 · Wwbn+2 · Avideo+1
CVE-2026-33731
·
Published
2026-06-22
·
Updated
2026-07-16
CVSS v3.1
6.5
Medium
| Vector | AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N |
Name of the Vulnerable Software and Affected Versions
AVideo versions prior to 29.0
Description
The Authorize.Net webhook handler at 'plugin/AuthorizeNet/webhook.php' contains a signature verification bypass. An attacker can forge webhook requests by providing a valid transaction ID from a small legitimate purchase, which allows them to bypass signature validation and credit arbitrary wallet balances to any user account using attacker-controlled payload fields. This is possible due to an exploit chain involving three flaws: a signature bypass using OR logic in
webhook.php, payload values overriding API-fetched values in AuthorizeNet.php and webhook.php, and a missing approval check in webhook.php before calling the processSinglePayment() function. By forging payment metadata, including the plans id variable, an attacker can activate premium subscriptions and gain free access to paid content, resulting in direct revenue loss for the platform owner.Recommendations
Update to version 29.0.
As a temporary workaround, restrict access to the 'plugin/AuthorizeNet/webhook.php' endpoint or disable the Authorize.Net plugin until the update is applied.
Exploit
Fix
Insufficient Verification of Data Authenticity
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Avideo
Wwbn Avideo