PT-2026-34227 · Avideo+1 · Clonesite+1

Published

2026-04-16

·

Updated

2026-04-25

·

CVE-2026-41304

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions WWBN AVideo versions 29.0 and earlier
Description The CloneSite plugin contains a flaw where the 'cloneServer.json.php' endpoint constructs shell commands using the url parameter without proper sanitization. This input is directly concatenated into a wget command executed via the exec() function, enabling command injection. An attacker can use shell metacharacters to execute arbitrary shell commands, leading to Remote Code Execution (RCE), which is the ability to execute any command on the target machine remotely.
Recommendations Update to the version containing commit 473c609fc2defdea8b937b00e86ce88eba1f15bb. As a temporary workaround, restrict access to the 'cloneServer.json.php' endpoint or avoid using the url parameter in the CloneSite plugin until the update is applied.

Exploit

Fix

RCE

OS Command Injection

Command Injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-41304
GHSA-XR6F-H4X7-R6QP

Affected Products

Avideo
Clonesite