Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2026-39366

24
FAUCET Score

WWBN AVideo versions 26.0 and earlier contain a transaction deduplication vulnerability in the legacy PayPal IPN v1 handler (plugin/PayPalYPT/ipn.php) that allows authenticated attackers to replay intercepted IPN notifications multiple times. This flaw enables attackers to arbitrarily inflate wallet balances and renew subscriptions indefinitely, despite newer handler versions correctly implementing deduplication controls. The vulnerable v1 endpoint remains actively configured as the default notify_url for billing plans, exposing all installations with PayPal integration enabled. The vulnerability carries a CVSS 6.5 medium severity rating with a network-based attack vector requiring valid user credentials but no user interaction. The impact is primarily integrity-focused, allowing unauthorized financial manipulation, though confidentiality and availability are not directly affected. The attack requires low complexity execution, making it accessible to any authenticated user within the platform. The vulnerability is not currently listed on CISA's Known Exploited Vulnerabilities catalog and shows minimal community attention, with an EPSS probability of 0.000160000 indicating extremely low real-world exploitation likelihood at present. No public exploit code or active exploitation has been confirmed. However, the straightforward nature of the attack and persistent default configuration of the vulnerable endpoint suggest remediation through version upgrades or disabling legacy PayPal handlers should be prioritized during routine maintenance windows.

Impacted Technologies

VendorProductVersion(s)CPE
<= 26.0CPE matchmatch criteria
cpe:2.3:a:wwbn:avideo:*:*:*:*:*:*:*:*

CVSS Data

CVSS version used by this source: 3.1

6.5MEDIUM

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N

Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
LOW
User Interaction
NONE
Scope
UNCHANGED
Confidentiality Impact
NONE
Integrity Impact
HIGH
Availability Impact
NONE
Exploitability Score
2.8
Impact Score
3.6
CvssVersion
3.1

Exploit Intelligence

EPSS Score
0.17%
Probability of exploitation in next 30 days
EPSS Percentile
6.6%
Percentile rank of EPSS score among Peer Group
As of 2026-07-27
Model: v2026.06.15
This CVE's current EPSS score of 0.0017 is in the 2nd percentile among its peer group of 21,958 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.

Media Mentions

No media coverage found for this CVE.

The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Patch Available

Vendor Patches (1)

github_advisorypatch availablevia nvd_reference
View patch

Vendor Advisories (1)

composerGHSA-mmw7-wq3c-wf9pmedium

WWBN AVideo Affected by a PayPal IPN Replay Attack Enabling Wallet Balance Inflation via Missing Transaction Deduplication in ipn.php

Apr 8, 2026

References

github.com / WWBN/AVideo/commit/8f53e9d9c6aaa07d51ace30691981edbbfb5ca1c
Patch
github.com / WWBN/AVideo/security/advisories/GHSA-mmw7-wq3c-wf9p
Third Party Advisory