CVE-2026-88871 | WWBN AVideo CustomizeUser setSubscribers.json.php setExtraSubscribers users_id/ExtraSubscribers cross-site request forgery

SecurityVulns

A vulnerability, which was classified as problematic, was found in WWBN AVideo. Affected by this issue is the function User::setExtraSubscribers of the file plugin/CustomizeUser/setSubscribers.json.php of the component CustomizeUser. Executing a manipulation of the argument users_id/ExtraSubscribers can lead to cross-site request forgery.

This vulnerability is registered as CVE-2026-88871. It is possible to launch the attack remotely. No exploit is available.

Applying a patch is advised to resolve this issue.VulDB Recent EntriesRead More