Stats Digest Feeds
โ† Back to all CVEs

CVE-2026-34737

MEDIUM NVD
CVSS Score 6.5
Severity MEDIUM
Published Mar 31, 2026
Vendor unknown

Description

WWBN AVideo is an open source video platform. In versions 26.0 and prior, the StripeYPT plugin includes a test.php debug endpoint that is accessible to any logged-in user, not just administrators. This endpoint processes Stripe webhook-style payloads and triggers subscription operations, including cancellation. Due to a bug in the retrieveSubscriptions() method that cancels subscriptions instead of merely retrieving them, any authenticated user can cancel arbitrary Stripe subscriptions by providing a subscription ID. At time of publication, there are no publicly available patches.

References