CVE-2026-86719 | WWBN AVideo CustomizeUser Plugin swapUser.json.php User::swapUser users_id cross-site request forgery
A vulnerability marked as problematic has been reported in WWBN AVideo. The impacted element is the function User::swapUser of the file plugin/CustomizeUser/swapUser.json.php of the component CustomizeUser Plugin. Performing a manipulation of the argument users_id results in cross-site request forgery.
This vulnerability is cataloged as CVE-2026-86719. It is possible to initiate the attack remotely. There is no exploit available.
It is recommended to apply a patch to fix this issue.VulDB Recent EntriesRead More