---
id: GHSA-rg7q-4223-phjw
title: >-
  Duplicate Advisory: AVideo: Unauthenticated Access to Payment Log DataTables
  Endpoints Exposes Transaction Data, PayPal Tokens, and User Financial Records
summary: >-
  Duplicate Advisory: AVideo: Unauthenticated Access to Payment Log DataTables
  Endpoints Exposes Transaction Data, PayPal Tokens, and User Financial Records
severity: high
cvss: 7.5
cwe:
  - CWE-862
vendor: wwbn
product: wwbn/avideo
ecosystem: composer
affected:
  - wwbn/avideo <= 26.0
published: '2026-06-20'
updated: '2026-09-09'
sourceUpdated: '2026-09-09T23:53:21Z'
source: GHSA
sourceUrl: 'https://github.com/advisories/GHSA-rg7q-4223-phjw'
references:
  - url: 'https://github.com/WWBN/AVideo/security/advisories/GHSA-wprj-9cvc-5w37'
  - url: 'https://nvd.nist.gov/vuln/detail/CVE-2026-56341'
  - url: >-
      https://www.vulncheck.com/advisories/avideo-unauthenticated-access-to-payment-log-datatables-endpoints-via-list-json-php
  - url: 'https://github.com/advisories/GHSA-rg7q-4223-phjw'
tags:
  - ghsa
  - composer
ingestedAt: '2026-09-10T00:26:24.579Z'
---

## Overview

### Duplicate Advisory
This advisory has been withdrawn because it is a duplicate of GHSA-wprj-9cvc-5w37. This link is maintained to preserve external references.

### Original Description
AVideo through version 26.0 contains multiple unauthenticated list.json.php endpoints in payment plugins lacking authorization checks, exposing PayPal tokens, Authorize.Net webhooks, and Bitcoin transaction records. Unauthenticated attackers can retrieve all payment transaction data including agreement IDs, user financial records, and API responses via direct GET requests to vulnerable endpoints.

## Affected packages

- `wwbn/avideo <= 26.0`

## Remediation

Refer to the advisory for the patched release.
