PT-2026-94096 · Avideo · Loginwordpress+1

·

CVE-2026-92579

·

Published

2026-09-16

·

Updated

2026-09-24

CVSS v3.1

5.4

Medium

VectorAV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:L
Name of the Vulnerable Software and Affected Versions AVideo versions prior to 29.1
Description The autoCSRFGuard() function uses a hardcoded allowlist of exempt basenames that are tested without directory context. This allows plugin files that share names with core filenames to inherit Cross-Site Request Forgery (CSRF) exemptions. Specifically, the LoginWordPress plugin file login.json.php inherits such an exemption, which allows it to unconditionally log out authenticated users during cross-site POST requests before credentials are validated.
Recommendations Update to a version newer than 29.0. As a temporary mitigation, restrict access to the login.json.php file within the LoginWordPress plugin.

Exploit

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-92579
GHSA-3HG6-6X7M-5XR8

Affected Products

Avideo
Loginwordpress