PT-2026-34227 · Avideo+1 · Clonesite+1
Published
2026-04-16
·
Updated
2026-04-25
·
CVE-2026-41304
CVSS v3.1
9.8
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
WWBN AVideo versions 29.0 and earlier
Description
The CloneSite plugin contains a flaw where the 'cloneServer.json.php' endpoint constructs shell commands using the
url parameter without proper sanitization. This input is directly concatenated into a wget command executed via the exec() function, enabling command injection. An attacker can use shell metacharacters to execute arbitrary shell commands, leading to Remote Code Execution (RCE), which is the ability to execute any command on the target machine remotely.Recommendations
Update to the version containing commit 473c609fc2defdea8b937b00e86ce88eba1f15bb.
As a temporary workaround, restrict access to the 'cloneServer.json.php' endpoint or avoid using the
url parameter in the CloneSite plugin until the update is applied.Exploit
Fix
RCE
OS Command Injection
Command Injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Avideo
Clonesite