CVE-2026-34375 is a high-severity Cross-Site Scripting (XSS) vulnerability impacting WWBN AVideo versions up to and including 26.0. The flaw allows an attacker to inject arbitrary JavaScript into the YPTWallet Stripe payment confirmation page by crafting a malicious URL that exploits an unsanitized 'plugin' parameter. With a CVSS score of 8.2, successful exploitation requires user interaction and can lead to high confidentiality impact, specifically the exfiltration of user usernames and password hashes. There are currently no known public exploits, active exploitation, or KEV listing, though the vulnerability has received limited discussion within security communities.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 26.0CPE matchmatch criteria | cpe:2.3:a:wwbn:avideo:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:L/A:N
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.2 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.1 Security Researcher mentions.