PT-2026-30985 · Paypalypt+1 · Paypalypt+1

Offset

·

Published

2026-04-07

·

Updated

2026-04-08

·

CVE-2026-39366

CVSS v3.1

6.5

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N
Name of the Vulnerable Software and Affected Versions AVideo versions 26.0 and prior
Description The AVideo platform, an open source video platform, has an issue in the PayPal IPN v1 handler located at 'plugin/PayPalYPT/ipn.php'. This handler does not properly deduplicate transactions, which could allow an attacker to replay a legitimate IPN notification multiple times. This replay could lead to an attacker inflating their wallet balance and renewing subscriptions repeatedly. The newer 'ipnV2.php' and 'webhook.php' handlers correctly deduplicate transactions using PayPalYPT log entries, but the vulnerable v1 handler remains in use as the notify url for billing plans.
Recommendations Update AVideo to a version later than 26.0.

Exploit

Fix

Insufficient Verification of Data Authenticity

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-39366
GHSA-MMW7-WQ3C-WF9P

Affected Products

Avideo
Paypalypt