CVE-2026-34394 | WWBN AVideo up to 26.0 Admin Plugin Configuration Endpoint admin/save.json.php isGlobalTokenValid/verifyToken cross-site request forgery (GHSA-4wwr-7h7c-chqr)
A vulnerability was found in WWBN AVideo up to 26.0 and classified as problematic. This issue affects the function isGlobalTokenValid/verifyToken of the file admin/save.json.php of the component Admin Plugin Configuration Endpoint. Such manipulation leads to cross-site request forgery.
This vulnerability is uniquely identified as CVE-2026-34394. The attack can be launched remotely. No exploit exists.