CVE-2026-84480
WWBN AVideo fails to validate password recovery token expiration in userRecoverPassSave.json.php, allowing attackers to use expired tokens to reset account passwords indefinitely. Attackers who obtain a recovery token can use it at any time to change the target account's password and gain full account access.
- Published Sep 1, 2026
- CVSS 9.3 critical
- 0.5% chance of exploitation in the next 30 days (EPSS)