WWBN AVideo versions 26.0 and earlier contain a transaction deduplication vulnerability in the legacy PayPal IPN v1 handler (plugin/PayPalYPT/ipn.php) that allows authenticated attackers to replay intercepted IPN notifications multiple times. This flaw enables attackers to arbitrarily inflate wallet balances and renew subscriptions indefinitely, despite newer handler versions correctly implementing deduplication controls. The vulnerable v1 endpoint remains actively configured as the default notify_url for billing plans, exposing all installations with PayPal integration enabled. The vulnerability carries a CVSS 6.5 medium severity rating with a network-based attack vector requiring valid user credentials but no user interaction. The impact is primarily integrity-focused, allowing unauthorized financial manipulation, though confidentiality and availability are not directly affected. The attack requires low complexity execution, making it accessible to any authenticated user within the platform. The vulnerability is not currently listed on CISA's Known Exploited Vulnerabilities catalog and shows minimal community attention, with an EPSS probability of 0.000160000 indicating extremely low real-world exploitation likelihood at present. No public exploit code or active exploitation has been confirmed. However, the straightforward nature of the attack and persistent default configuration of the vulnerable endpoint suggest remediation through version upgrades or disabling legacy PayPal handlers should be prioritized during routine maintenance windows.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 26.0CPE matchmatch criteria | cpe:2.3:a:wwbn:avideo:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.