WWBN AVideo through commit 9c39d8c8 contains a cross-site request forgery (CSRF) vulnerability in the releaseVideoNow.json.php endpoint. The endpoint lacks authenticity/CSRF token checks and accepts GET requests, making it susceptible to exploitation. An attacker can craft a malicious cross-site GET request that leverages an authenticated administrator's session cookie. By manipulating the videos_id parameter, the attacker can permanently publish any embargoed or restricted video without authorization. This vulnerability requires the victim administrator to be logged in and visit or load a malicious resource. The impact is unauthorized modification of content visibility settings on affected AVideo installations. Administrators and site operators using AVideo should apply patches or mitigations as referenced in the GitHub security advisory and VulnCheck advisory.