Incomplete fix for CVE-2026-43881
CVE-2026-45620 is a medium-severity vulnerability affecting WWBN/AVideo (PHP): Incomplete fix for CVE-2026-43881.
Reported by Kai Aizen. Status: Published. Coordinated through standard NVD/MITRE/GHSA channels.
CVE-2026-45620 is a disclosed vulnerability (Disclosed vulnerability) in WWBN/AVideo, coordinated through the standard CVE process by independent security researcher Kai Aizen.
You are affected if your environment runs an unpatched version of WWBN/AVideo. Check the upstream advisory or NVD record for the precise affected version range, then verify against your deployed version.
Upgrade WWBN/AVideo to the version that includes the upstream fix referenced in the NVD record. If an immediate upgrade is not possible, apply the mitigation guidance from the vendor advisory and restrict exposure of the affected surface area.
CVSS — · Medium. The vulnerability class is Disclosed vulnerability; consult the NVD and vendor advisory for vector details, exploitation prerequisites, and observed impact.
NVD record at https://nvd.nist.gov/vuln/detail/CVE-2026-45620, the MITRE CVE record at https://www.cve.org/CVERecord?id=CVE-2026-45620, and the vendor's security advisory page.