PT-2026-94096 · Avideo · Loginwordpress+1
CVSS v3.1
5.4
Medium
| Vector | AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:L |
Name of the Vulnerable Software and Affected Versions
AVideo versions prior to 29.1
Description
The
autoCSRFGuard() function uses a hardcoded allowlist of exempt basenames that are tested without directory context. This allows plugin files that share names with core filenames to inherit Cross-Site Request Forgery (CSRF) exemptions. Specifically, the LoginWordPress plugin file login.json.php inherits such an exemption, which allows it to unconditionally log out authenticated users during cross-site POST requests before credentials are validated.Recommendations
Update to a version newer than 29.0.
As a temporary mitigation, restrict access to the
login.json.php file within the LoginWordPress plugin.Exploit
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Avideo
Loginwordpress