VYPR
Medium severity5.4NVD Advisory· Published Sep 8, 2026

CVE-2026-86719

CVE-2026-86719

Description

WWBN AVideo through commit c3edcc274c389816d434acadac07ee78eaf330c1 (master) contains a cross-site request forgery vulnerability in the CustomizeUser plugin endpoint plugin/CustomizeUser/swapUser.json.php. The endpoint takes users_id from $_REQUEST and invokes User::swapUser() without calling forbidIfNotPost() or forbidIfInvalidToken(), and the global autoCSRFGuard() check only runs for POST requests to *.json.php, so the action is reachable via GET. An attacker who causes an authenticated administrator's browser to issue a cross-origin GET (for example via an tag or link) can replace that administrator's session with a non-admin user account, causing the administrator to lose administrative access until the swap is cancelled; swapping to another administrator account is rejected, so this is not privilege escalation. The JSON response also discloses the session_id. The CustomizeUser plugin is enabled by default, and no patch was available at the time of publication.

Affected products

1
  • WWBN/Avideollm-fuzzy
    Range: through commit c3edcc274c389816d434acadac07ee78eaf330c1 (master)

Patches

Vulnerability mechanics

References

2

News mentions

0

No linked articles in our index yet.