WWBN AVideo patched a critical stored DOM-based cross-site scripting flaw, tracked as CVE-2026-54458, in the YPTSocket plugin affecting versions before 29.0. The vulnerability lets an unauthenticated remote attacker obtain a signed WebSocket token, inject malicious values through WebSocket connection parameters, and have attacker-controlled HTML or JavaScript broadcast to connected users and rendered in the online-users debug panel. If an administrator views a page displaying that panel, the attacker can execute arbitrary JavaScript in the admin’s authenticated browser session.
The impact includes theft of non-HttpOnly cookies and CSRF tokens, execution of admin-only actions, exfiltration of dashboard data, and possible full administrative takeover. A related GitHub fix updated plugin/YPTSocket/MessageSQLiteV2.php to validate webSocketSelfURI so only http and https URLs are accepted, blocking javascript: URI injection, and to sanitize page_title with HTML escaping to prevent script injection from untrusted input. The issue carries a CVSS 3.1 score of 9.6 and is classified as CWE-79.

See affected versions and whether adversaries are exploiting it.
2 events from the most recent confirmed update back to the earliest known activity.
CVE-2026-54458 was published as a critical stored DOM-based XSS vulnerability in the YPTSocket plugin of WWBN AVideo affecting versions before 29.0. The disclosure states the flaw could let an unauthenticated attacker broadcast malicious HTML/JavaScript to connected clients and potentially achieve administrative takeover if an admin renders the affected panel.
A GitHub commit modified plugin/YPTSocket/MessageSQLiteV2.php to validate webSocketSelfURI to only allow http/https URLs and to HTML-encode page_title, mitigating injection risks in the YPTSocket component.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See whether adversaries are exploiting this yet, and where the affected versions run in your environment.
2 references tracked. Mallory keeps watching after this page renders.
cvefeed.io
Open sourcegithub.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.