THREAT OPS › Threat News › [NVD] CVE-2026-92579 (MEDIUM 5.4) — In AVideo through 29.0, the autoCSRFGuard() function maintains a hardcoded allowlist of exempt basenames tested without directory context, allowing plugin files matching core filenames to inherit CSRF exemptions. The LoginWordPress plugin file login.json.php inherits an exemption
[NVD] CVE-2026-92579 (MEDIUM 5.4) — In AVideo through 29.0, the autoCSRFGuard() function maintains a hardcoded allowlist of exempt basenames tested without directory context, allowing plugin files matching core filenames to inherit CSRF exemptions. The LoginWordPress plugin file login.json.php inherits an exemption
CVE-2026-92579 CVSS: 5.4 MEDIUM Published: 2026-09-16T22:18:28.193
In AVideo through 29.0, the autoCSRFGuard() function maintains a hardcoded allowlist of exempt basenames tested without directory context, allowing plugin files matching core filenames to inherit CSRF exemptions. The LoginWordPress plugin file login.json.php inherits an exemption and unconditionally logs out authenticated users on
MITRE ATT&CK techniques
- CredentialsT1589.001
Indicators of compromise
- CVE-2026-92579cve
Original source: https://nvd.nist.gov/vuln/detail/CVE-2026-92579