WWBN AVideo Affected by a PayPal IPN Replay Attack Enabling Wallet Balance Inflation via Missing Transaction Deduplication in ipn.php
Published Apr 7, 2026
6.5
MEDIUMCVSS 3.1
EPSS 0.19%
Description
WWBN AVideo is an open source video platform. In versions 26.0 and prior, the PayPal IPN v1 handler at plugin/PayPalYPT/ipn.php lacks transaction deduplication, allowing an attacker to replay a single legitimate IPN notification to repeatedly inflate their wallet balance and renew subscriptions. The newer ipnV2.php and webhook.php handlers correctly deduplicate via PayPalYPT_log entries, but the v1 handler was never updated and remains actively referenced as the notify_url for billing plans.
Affected products
-
- Version <= 26.0StatusaffectedConstraints-
- Version
No data.
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
No remediation recorded yet.
Metrics
No CVSS v4.0 score for this CVE.
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N
No CVSS v3.0 score for this CVE.
No CVSS v2.0 score for this CVE.
This CVE is not in the KEV list.
CISA SSVC (Vulnrichment)
Stakeholder-Specific Vulnerability Categorization from CISA ADP.
Exploitation
PoCAutomatable
NoTechnical Impact
PartialDecision
n/aAssessed Apr 8, 2026 · SSVC 2.0.3
Estimated probability of exploitation in the wild in the next 30 days (FIRST EPSS). As of Oct 2, 2026.
Score over time
Apr–Oct 2026- EPSS v4
- EPSS v5
Percentile over time
- EPSS v4
- EPSS v5
Table of values (3 key points)
Flat stretches are collapsed; showing up to 120 newest points.
| Date | Score | Percentile | Model |
|---|---|---|---|
| Oct 2, 2026 | 0.19% (0.00186) | 7.37th | v5 (v2026.06.15) |
| Jun 15, 2026 | 0.17% (0.00170) | 6.58th | v5 (v2026.06.15) |
| Apr 8, 2026 | 0.01% (0.00014) | 2.73th | v4 (v2025.03.14) |
References (4)
- https://github.com/WWBN/AVideo/commit/8f53e9d9c6aaa07d51ace30691981edbbfb5ca1c x_refsource_MISCPatch
- https://github.com/WWBN/AVideo/security/advisories/GHSA-mmw7-wq3c-wf9p exploitx_refsource_CONFIRMThird Party Advisory
- https://github.com/advisories/GHSA-mmw7-wq3c-wf9p Advisory
- https://nvd.nist.gov/vuln/detail/CVE-2026-39366
| Link | Providers | Tags |
|---|---|---|
| https://github.com/WWBN/AVideo/commit/8f53e9d9c6aaa07d51ace30691981edbbfb5ca1c | x_refsource_MISCPatch | |
| https://github.com/WWBN/AVideo/security/advisories/GHSA-mmw7-wq3c-wf9p | exploitx_refsource_CONFIRMThird Party Advisory | |
| https://github.com/advisories/GHSA-mmw7-wq3c-wf9p | Advisory | |
| https://nvd.nist.gov/vuln/detail/CVE-2026-39366 |
Change history (0)
No recorded changes yet.