Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Wed, 16 Sep 2026 22:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | In AVideo through 29.0, the autoCSRFGuard() function maintains a hardcoded allowlist of exempt basenames tested without directory context, allowing plugin files matching core filenames to inherit CSRF exemptions. The LoginWordPress plugin file login.json.php inherits an exemption and unconditionally logs out authenticated users on cross-site POST requests before validating credentials. | |
| Title | AVideo through 29.0 Broken Access Control via CSRF Exemption Basename Collision | |
| First Time appeared |
Wwbn
Wwbn avideo |
|
| Weaknesses | CWE-289 | |
| CPEs | cpe:2.3:a:wwbn:avideo:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Wwbn
Wwbn avideo |
|
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: VulnCheck
Published:
Updated: 2026-09-16T21:46:47.891Z
Reserved: 2026-09-16T13:47:20.117Z
Link: CVE-2026-92579
No data.
Status : Received
Published: 2026-09-16T22:18:28.193
Modified: 2026-09-16T22:18:28.193
Link: CVE-2026-92579
No data.
OpenCVE Enrichment
No data.
-
CWE-289
Authentication Bypass by Alternate Name