CVE-2026-33478 describes a critical remote code execution (RCE) vulnerability affecting WWBN AVideo versions up to and including 26.0. This RCE is achieved by chaining multiple flaws within the CloneSite plugin, allowing a completely unauthenticated attacker to compromise the system. Rated 10.0 Critical, the vulnerability has a network attack vector, low attack complexity, and high impact on confidentiality, integrity, and availability. Successful exploitation grants an attacker full control over the affected system, including arbitrary command execution. While not currently listed on CISA KEV or the Hot List, and with no public exploit code available, its low EPSS score suggests a relatively low probability of exploitation in the wild despite minimal community discussion.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 26.0CPE matchmatch criteria | cpe:2.3:a:wwbn:avideo:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.