PT-2026-29364 · WordPress+1 · Stripeypt+1

Adrgs

·

Published

2026-03-31

·

Updated

2026-04-01

·

CVE-2026-34737

CVSS v3.1

6.5

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N
Name of the Vulnerable Software and Affected Versions AVideo versions 26.0 and prior
Description AVideo is an open source video platform. A debug endpoint, test.php, within the StripeYPT plugin is accessible to all logged-in users, not just administrators. This endpoint processes Stripe webhook-style payloads and triggers subscription operations, including cancellation. A flaw in the retrieveSubscriptions() method causes subscriptions to be cancelled instead of retrieved. This allows any authenticated user to cancel arbitrary Stripe subscriptions by providing a subscription ID.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Missing Authorization

Weakness Enumeration

Related Identifiers

CVE-2026-34737
GHSA-38RH-4V39-VFXV

Affected Products

Avideo
Stripeypt