plugin

Fv Wordpress Flowplayer Vulnerabilities

62 known security issues reported for the Fv Wordpress Flowplayer WordPress plugin. Most recent disclosed Jun 30, 2026.

3 critical 3 high 21 medium

Running Fv Wordpress Flowplayer on your site? Check whether your installed version is affected.

Scan your site free

FV Flowplayer Video Player <= 7.5.51.7212 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'video_player' Shortcode

medium

The FV Flowplayer Video Player plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'video_player' shortcode 'align' attribute in all versions up to, and including, 7.5.51.7212 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authent...

CVSS:
6.4
Affected:
up to 7.5.51.7212
Fixed in:
7.5.52.7212
Disclosed:
Jun 30, 2026

CVE-2026-12135 on NVD →

FV Flowplayer Video Player <= 7.5.49.7212 - Unauthenticated Stored Cross-Site Scripting via Comment Text

high

The FV Flowplayer Video Player plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the comment text in all versions up to, and including, 7.5.49.7212 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in page...

CVSS:
7.2
Affected:
up to 7.5.49.7212
Fixed in:
7.5.50.7212
Disclosed:
Jun 8, 2026

CVE-2026-7556 on NVD →

FV Flowplayer Video Player < 7.5.51.7212 - Authenticated (Subscriber+) Stored Cross-Site Scripting

medium

The FV Flowplayer Video Player plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to 7.5.51.7212 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with subscriber-level access and above, to inject arbitrary web scripts in pages...

CVSS:
6.4
Affected:
up to 7.5.51.7212
Fixed in:
7.5.51.7212
Disclosed:
Jun 4, 2026

CVE-2026-49773 on NVD →

FV Flowplayer Video Player [fv-wordpress-flowplayer] < 7.5.48.7212

unknown

[en] Multiple plugins for WordPress are vulnerable to Stored Cross-Site Scripting via the plugin's bundled FancyBox JavaScript library (versions 1.3.4 to 3.5.7) in various versions due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers,...

Affected:
up to 7.5.48.7212
Fixed in:
7.5.48.7212
Disclosed:
Dec 4, 2024

CVE-2024-5020 on NVD →

Multiple Plugins <= (Various Versions) - Authenticated (Contributor+) Stored DOM-Based Cross-Site Scripting via FancyBox JavaScript Library

medium

Multiple plugins for WordPress are vulnerable to Stored Cross-Site Scripting via the plugin's bundled FancyBox JavaScript library (versions 1.3.4 to 3.5.7) in various versions due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with...

CVSS:
6.4
Affected:
up to 7.5.47.7212
Fixed in:
7.5.48.7212
Disclosed:
Dec 3, 2024

CVE-2024-5020 on NVD →

FV Flowplayer Video Player [fv-wordpress-flowplayer] < 7.5.47.7212

unknown

[en] The FV Flowplayer Video Player plugin for WordPress is vulnerable to time-based SQL Injection via the ‘exclude’ parameter in all versions up to, and including, 7.5.46.7212 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possib...

Affected:
up to 7.5.47.7212
Fixed in:
7.5.47.7212
Disclosed:
Jul 19, 2024

CVE-2024-6338 on NVD →

FV Player <= 7.5.46.7212 - Authenticated (Subscriber+) SQL Injection via exclude Parameter

high

The FV Flowplayer Video Player plugin for WordPress is vulnerable to time-based SQL Injection via the ‘exclude’ parameter in all versions up to, and including, 7.5.46.7212 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible fo...

CVSS:
8.8
Affected:
up to 7.5.46.7212
Fixed in:
7.5.47.7212
Disclosed:
Jul 18, 2024

CVE-2024-6338 on NVD →

FV Flowplayer Video Player [fv-wordpress-flowplayer] < 7.5.46.7212

unknown

[en] Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Foliovision FV Flowplayer Video Player allows Reflected XSS.This issue affects FV Flowplayer Video Player: from n/a through 7.5.45.7212.

Affected:
up to 7.5.46.7212
Fixed in:
7.5.46.7212
Disclosed:
Jun 3, 2024

CVE-2024-35631 on NVD →

FV Flowplayer Video Player <= 7.5.45.7212 - Reflected Cross-Site Scripting

medium

The FV Flowplayer Video Player plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in all versions up to, and including, 7.5.45.7212 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if...

CVSS:
6.1
Affected:
up to 7.5.45.7212
Fixed in:
7.5.46.7212
Disclosed:
May 27, 2024

CVE-2024-35631 on NVD →

FV Flowplayer Video Player [fv-wordpress-flowplayer] < 7.5.45.7212

unknown

[en] URL Redirection to Untrusted Site ('Open Redirect') vulnerability in Foliovision FV Flowplayer Video Player.This issue affects FV Flowplayer Video Player: from n/a through 7.5.44.7212.

Affected:
up to 7.5.45.7212
Fixed in:
7.5.45.7212
Disclosed:
Apr 24, 2024

CVE-2024-32078 on NVD →

FV Flowplayer Video Player [fv-wordpress-flowplayer] < 7.5.45.7212

unknown

[en] Server-Side Request Forgery (SSRF) vulnerability in Foliovision FV Flowplayer Video Player.This issue affects FV Flowplayer Video Player: from n/a through 7.5.43.7212.

Affected:
up to 7.5.45.7212
Fixed in:
7.5.45.7212
Disclosed:
Apr 24, 2024

CVE-2024-32955 on NVD →

FV Flowplayer Video Player <= 7.5.43.7212 - Authenticated (Subscriber+) Server-side Request Forgery

medium

The FV Flowplayer Video Player plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 7.5.43.7212. This makes it possible for authenticated attackers, with subscriber-level access and above, to make web requests to arbitrary locations originating from the web application...

CVSS:
6.4
Affected:
up to 7.5.43.7212
Fixed in:
7.5.45.7212
Disclosed:
Apr 22, 2024

CVE-2024-32955 on NVD →

FV Flowplayer Video Player <= 7.5.44.7212 - Authenticated (Contributor+) Arbitrary Redirect

medium

The FV Flowplayer Video Player plugin for WordPress is vulnerable to unauthorized redirects in all versions up to, and including, 7.5.44.7212. This is due to the plugin not restricting contributor and above users from being able to add redirects at the end of videos. This makes it possible for authenticated attackers,...

CVSS:
5.4
Affected:
up to 7.5.44.7212
Fixed in:
7.5.45.7212
Disclosed:
Apr 11, 2024

CVE-2024-32078 on NVD →

FV Flowplayer Video Player [fv-wordpress-flowplayer] < 7.5.44.7212

unknown

[en] Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Foliovision: Making the web work for you FV Flowplayer Video Player allows Reflected XSS.This issue affects FV Flowplayer Video Player: from n/a through 7.5.41.7212.

Affected:
up to 7.5.44.7212
Fixed in:
7.5.44.7212
Disclosed:
Mar 27, 2024

CVE-2024-22299 on NVD →

FV Flowplayer Video Player <= 7.5.41.7212 - Reflected Cross-Site Scripting

medium

The FV Flowplayer Video Player plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and including, 7.5.41.7212 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they...

CVSS:
6.1
Affected:
up to 7.5.41.7212
Fixed in:
7.5.44.7212
Disclosed:
Mar 26, 2024

CVE-2024-22299 on NVD →

FV Flowplayer Video Player [fv-wordpress-flowplayer] < 7.5.44.7212

unknown

[en] Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Foliovision: Making the web work for you FV Flowplayer Video Player allows Stored XSS.This issue affects FV Flowplayer Video Player: from n/a through 7.5.41.7212.

Affected:
up to 7.5.44.7212
Fixed in:
7.5.44.7212
Disclosed:
Mar 19, 2024

CVE-2024-29122 on NVD →

FV Flowplayer Video Player <= 7.5.41.7212 - Authenticated (Contributor+) Stored Cross-Site Scripting

medium

The FV Flowplayer Video Player plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 7.5.41.7212 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web...

CVSS:
6.4
Affected:
up to 7.5.41.7212
Fixed in:
7.5.44.7212
Disclosed:
Mar 16, 2024

CVE-2024-29122 on NVD →

FV Flowplayer Video Player [fv-wordpress-flowplayer] < 7.5.39.7212

unknown

[en] The FV Flowplayer Video Player plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘_fv_player_user_video’ parameter saved via the 'save' function hooked via init, and the plugin is also vulnerable to Arbitrary Usermeta Update via the 'save' function in versions up to, and including, 7.5.37.7...

Affected:
up to 7.5.39.7212
Fixed in:
7.5.39.7212
Disclosed:
Aug 25, 2023

CVE-2023-4520 on NVD →

FV Flowplayer Video Player <= 7.5.37.7212 - Insufficient Input Validation to Unauthenticated Stored Cross-Site Scripting and Arbitrary Usermeta Update

medium

The FV Flowplayer Video Player plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘_fv_player_user_video’ parameter saved via the 'save' function hooked via init, and the plugin is also vulnerable to Arbitrary Usermeta Update via the 'save' function in versions up to, and including, 7.5.37.7212 d...

CVSS:
5.4
Affected:
up to 7.5.37.7212
Fixed in:
7.5.39.7212
Disclosed:
Aug 24, 2023

CVE-2023-4520 on NVD →

FV Flowplayer Video Player [fv-wordpress-flowplayer] < 7.5.39.7212

unknown

The FV Flowplayer Video Player plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘_fv_player_user_video’ parameter saved via the 'save' function hooked via init, and the plugin is also vulnerable to Arbitrary Usermeta Update via the 'save' function in versions up to, and including, 7.5.37.7212 d...

Affected:
up to 7.5.39.7212
Fixed in:
7.5.39.7212
Disclosed:
Aug 24, 2023

FV Flowplayer Video Player [fv-wordpress-flowplayer] < 7.5.35.7212

unknown

[en] Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in FolioVision FV Flowplayer Video Player plugin <= 7.5.32.7212 versions.

Affected:
up to 7.5.35.7212
Fixed in:
7.5.35.7212
Disclosed:
Aug 18, 2023

CVE-2023-30499 on NVD →

FV Flowplayer Video Player <= 7.5.32.7212 - Reflected Cross-Site Scripting via id

medium

The FV Flowplayer Video Player plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘id’ parameter in versions up to, and including, 7.5.32.7212 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pag...

CVSS:
6.1
Affected:
up to 7.5.32.7212
Fixed in:
7.5.35.7212
Disclosed:
May 3, 2023

CVE-2023-30499 on NVD →

FV Flowplayer Video Player [fv-wordpress-flowplayer] < 7.5.31.7212

unknown

[en] Cross-Site Request Forgery (CSRF) vulnerability in FolioVision FV Flowplayer Video Player plugin <= 7.5.30.7212 versions.

Affected:
up to 7.5.31.7212
Fixed in:
7.5.31.7212
Disclosed:
Feb 14, 2023

CVE-2023-25066 on NVD →

FV Flowplayer Video Player <= 7.5.30.7210 - Cross-Site Request Forgery

medium

The FV Flowplayer Video Player plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 7.5.30.7210. This is due to missing or incorrect nonce validation on the settings_toggle() function. This makes it possible for unauthenticated attackers to modify the plugin's settings via...

CVSS:
4.3
Affected:
up to 7.5.30.7210
Fixed in:
7.5.31.7212
Disclosed:
Feb 2, 2023

CVE-2023-25066 on NVD →

FV Flowplayer Video Player <= 7.5.18.727 - Stored Cross-Site Scripting

medium

Authenticated Persistent Cross-Site Scripting (XSS) vulnerability in FV Flowplayer Video Player (WordPress plugin) versions <= 7.5.18.727 via &fv_wp_flowplayer_field_splash parameter.

CVSS:
6.4
Affected:
up to 7.5.18.727
Fixed in:
7.5.19.728
Disclosed:
Apr 4, 2022

CVE-2022-25613 on NVD →

FV Flowplayer Video Player [fv-wordpress-flowplayer] < 7.5.19.728

unknown

[en] Authenticated Persistent Cross-Site Scripting (XSS) vulnerability in FV Flowplayer Video Player (WordPress plugin) versions <= 7.5.18.727 via &fv_wp_flowplayer_field_splash parameter.

Affected:
up to 7.5.19.728
Fixed in:
7.5.19.728
Disclosed:
Apr 4, 2022

CVE-2022-25613 on NVD →

FV Flowplayer Video Player <= 7.5.15.727 - SQL Injection

high

Authenticated (author or higher user role) SQL Injection (SQLi) vulnerability discovered in FV Flowplayer Video Player WordPress plugin (versions <= 7.5.15.727).

CVSS:
7.2
Affected:
up to 7.5.15.727
Fixed in:
7.5.18.727
Disclosed:
Mar 18, 2022

CVE-2022-25607 on NVD →

FV Flowplayer Video Player [fv-wordpress-flowplayer] < 7.5.18.727

unknown

[en] Authenticated (author or higher user role) SQL Injection (SQLi) vulnerability discovered in FV Flowplayer Video Player WordPress plugin (versions <= 7.5.15.727).

Affected:
up to 7.5.18.727
Fixed in:
7.5.18.727
Disclosed:
Mar 18, 2022

CVE-2022-25607 on NVD →

FV Flowplayer Video Player [fv-wordpress-flowplayer] >= 7.5.0.727 - <= 7.5.2.727

unknown

[en] The FV Flowplayer Video Player WordPress plugin is vulnerable to Reflected Cross-Site Scripting via the player_id parameter found in the ~/view/stats.php file which allows attackers to inject arbitrary web scripts, in versions 7.5.0.727 - 7.5.2.727.

Affected:
7.5.0.727 – 7.5.2.727
Fixed in:
7.5.2.727
Disclosed:
Oct 6, 2021

CVE-2021-39350 on NVD →

FV Flowplayer Video Player 7.5.0.727 - 7.5.2.727 - Reflected Cross-Site Scripting via player_id Parameter

medium

The FV Flowplayer Video Player WordPress plugin is vulnerable to Reflected Cross-Site Scripting via the player_id parameter found in the ~/view/stats.php file which allows attackers to inject arbitrary web scripts, in versions 7.5.0.727 - 7.5.2.727.

CVSS:
6.1
Affected:
7.5.0.727 – 7.5.2.727
Fixed in:
7.5.3.727
Disclosed:
Oct 5, 2021

CVE-2021-39350 on NVD →

FV Flowplayer Video Player <= 7.4.37.727 - Authenticated Stored Cross-Site Scripting

medium

Cross-site scripting (XSS) vulnerability in models/list-table.php in the FV Flowplayer Video Player plugin before 7.4.37.727 for WordPress allows remote authenticated users to inject arbitrary web script or HTML via the fv_wp_fvvideoplayer_src JSON field in the data parameter.

CVSS:
6.4
Affected:
up to 7.4.37.727
Fixed in:
7.4.38.727
Disclosed:
Jan 15, 2021

CVE-2020-35748 on NVD →

FV Flowplayer Video Player [fv-wordpress-flowplayer] < 7.4.37.727

unknown

[en] Cross-site scripting (XSS) vulnerability in models/list-table.php in the FV Flowplayer Video Player plugin before 7.4.37.727 for WordPress allows remote authenticated users to inject arbitrary web script or HTML via the fv_wp_fvvideoplayer_src JSON field in the data parameter.

Affected:
up to 7.4.37.727
Fixed in:
7.4.37.727
Disclosed:
Jan 15, 2021

CVE-2020-35748 on NVD →

FV Flowplayer Video Player [fv-wordpress-flowplayer] < 7.3.15.727

unknown

[en] The FV Flowplayer Video Player plugin before 7.3.15.727 for WordPress allows guests to obtain the email subscription list in CSV format via the wp-admin/admin-post.php?page=fvplayer&fv-email-export=1 URI.

Affected:
up to 7.3.15.727
Fixed in:
7.3.15.727
Disclosed:
Aug 15, 2019

CVE-2019-14800 on NVD →

FV Flowplayer Video Player [fv-wordpress-flowplayer] < 7.3.14.727

unknown

[en] The FV Flowplayer Video Player plugin before 7.3.14.727 for WordPress allows email subscription XSS.

Affected:
up to 7.3.14.727
Fixed in:
7.3.14.727
Disclosed:
Aug 9, 2019

CVE-2019-14799 on NVD →

FV Flowplayer Video Player [fv-wordpress-flowplayer] < 7.3.15.727

unknown

[en] The FV Flowplayer Video Player plugin before 7.3.15.727 for WordPress allows email subscription SQL injection.

Affected:
up to 7.3.15.727
Fixed in:
7.3.15.727
Disclosed:
Aug 9, 2019

CVE-2019-14801 on NVD →

FV Flowplayer Video Player [fv-wordpress-flowplayer] < 7.3.19.727

unknown

[en] A SQL injection vulnerability exists in the FolioVision FV Flowplayer Video Player plugin before 7.3.19.727 for WordPress. Successful exploitation of this vulnerability would allow a remote attacker to execute arbitrary SQL commands on the affected system.

Affected:
up to 7.3.19.727
Fixed in:
7.3.19.727
Disclosed:
Jul 17, 2019

CVE-2019-13573 on NVD →

FV Flowplayer Video Player [fv-wordpress-flowplayer] < 7.3.19.727

unknown

SQL Injection (SQLi) vulnerability found by Tin Duong in WordPress FV Flowplayer Video Player plugin (versions <= 7.3.18.727).

Affected:
up to 7.3.19.727
Fixed in:
7.3.19.727
Disclosed:
Jul 13, 2019

FV Flowplayer Video Player <= 7.3.18.727 - SQL Injection

critical

A SQL injection vulnerability exists in the FolioVision FV Flowplayer Video Player plugin before 7.3.19.727 for WordPress. Successful exploitation of this vulnerability would allow a remote attacker to execute arbitrary SQL commands on the affected system.

CVSS:
9.8
Affected:
up to 7.3.18.727
Fixed in:
7.3.19.727
Disclosed:
Jul 11, 2019

CVE-2019-13573 on NVD →

FV Flowplayer Video Player [fv-wordpress-flowplayer] < 7.3.15.727

unknown

CSV Export vulnerability found in WordPress FV Flowplayer Video Player plugin (versions <= 7.3.14.727).

Affected:
up to 7.3.15.727
Fixed in:
7.3.15.727
Disclosed:
May 21, 2019

FV Flowplayer Video Player [fv-wordpress-flowplayer] < 7.3.14.727

unknown

Unauthenticated Stored Cross-Site Scripting (XSS) vulnerability found in WordPress FV Flowplayer Video Player plugin (versions <= 7.3.13.727).

Affected:
up to 7.3.14.727
Fixed in:
7.3.14.727
Disclosed:
May 21, 2019

FV Flowplayer Video Player [fv-wordpress-flowplayer] < 7.3.15.727

unknown

SQL Injection (SQLi) vulnerability found in WordPress FV Flowplayer Video Player plugin (versions <= 7.3.14.727).

Affected:
up to 7.3.15.727
Fixed in:
7.3.15.727
Disclosed:
May 21, 2019

FV Flowplayer Video Player <= 7.3.14.727 - SQL Injection

critical

The FV Flowplayer Video Player plugin before 7.3.15.727 for WordPress allows email subscription SQL injection.

CVSS:
9.8
Affected:
up to 7.3.15.727
Fixed in:
7.3.15.727
Disclosed:
May 20, 2019

CVE-2019-14801 on NVD →

FV Flowplayer Video Player <= 7.3.13.727 - Unauthenticated Stored Cross-Site Scripting

medium

The FV Flowplayer Video Player plugin before 7.3.14.727 for WordPress allows email subscription XSS.

CVSS:
6.1
Affected:
up to 7.3.13.727
Fixed in:
7.3.14.727
Disclosed:
May 20, 2019

CVE-2019-14799 on NVD →

FV Flowplayer Video Player <= 7.3.14.727 - Sensitive Information Exposure

medium

The FV Flowplayer Video Player plugin before 7.3.15.727 for WordPress allows guests to obtain the email subscription list in CSV format via the wp-admin/admin-post.php?page=fvplayer&fv-email-export=1 URI.

CVSS:
5.3
Affected:
up to 7.3.14.727
Fixed in:
7.3.15.727
Disclosed:
May 20, 2019

CVE-2019-14800 on NVD →

FV Flowplayer Video Player <= 7.3.14.727 - Unauthenticated SQL Injection

critical

The FV Flowplayer Video Player plugin for WordPress is vulnerable to SQL injection in versions up to, and including, 7.3.14.727 in the 'email_signup' function. This makes it possible for Unauthenticated attackers to append additional SQL queries into already existing queries that can be used to extract sensitive inform...

CVSS:
9.3
Affected:
up to 7.3.15.727
Fixed in:
7.3.15.727
Disclosed:
May 16, 2019

FV Flowplayer Video Player <= 7.3.14.727 - Sensitive Data Exposure

medium

The FV Flowplayer Video Player plugin for WordPress is vulnerable to sensitive data exposure in versions up to, and including, 7.3.14.727 via the 'csv_export' function. This makes it possible for attackers to export a CSV of email subscribers.

CVSS:
5.3
Affected:
up to 7.3.15.727
Fixed in:
7.3.15.727
Disclosed:
May 16, 2019

FV Flowplayer Video Player [fv-wordpress-flowplayer] < 7.3.15.727

unknown

The FV Flowplayer Video Player plugin for WordPress is vulnerable to sensitive data exposure in versions up to, and including, 7.3.14.727 via the 'csv_export' function. This makes it possible for attackers to export a CSV of email subscribers.

Affected:
up to 7.3.15.727
Fixed in:
7.3.15.727
Disclosed:
May 16, 2019

FV Flowplayer Video Player [fv-wordpress-flowplayer] < 7.3.15.727

unknown

The FV Flowplayer Video Player plugin for WordPress is vulnerable to SQL injection in versions up to, and including, 7.3.14.727 in the 'email_signup' function. This makes it possible for Unauthenticated attackers to append additional SQL queries into already existing queries that can be used to extract sensitive inform...

Affected:
up to 7.3.15.727
Fixed in:
7.3.15.727
Disclosed:
May 16, 2019

FV Flowplayer Video Player [fv-wordpress-flowplayer] < 7.2.1.727

unknown

Authenticated Cross-Site Scripting (XSS) vulnerability found by Janek Vind "waraxe" in WordPress FV Flowplayer Video Player plugin (versions <= 7.2.0.727).

Affected:
up to 7.2.1.727
Fixed in:
7.2.1.727
Disclosed:
Oct 3, 2018

FV Flowplayer Video Player <= 7.2.0.727 - Reflected Cross-Site Scripting

medium

The FV Flowplayer Video Player plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘fv_player_preview’ parameter in versions up to, and including, 7.2.0.727 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web s...

CVSS:
6.1
Affected:
up to 7.2.0.727
Fixed in:
7.2.1.727
Disclosed:
Sep 21, 2018

FV Flowplayer Video Player [fv-wordpress-flowplayer] < 7.2.1.727

unknown

The FV Flowplayer Video Player plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘fv_player_preview’ parameter in versions up to, and including, 7.2.0.727 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web s...

Affected:
up to 7.2.1.727
Fixed in:
7.2.1.727
Disclosed:
Sep 21, 2018

FV Flowplayer Video Player [fv-wordpress-flowplayer] >= 6.1.2 - <= 6.6.4

unknown

[en] Cross-site scripting vulnerability in FV Flowplayer Video Player 6.1.2 to 6.6.4 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.

Affected:
6.1.2 – 6.6.4
Fixed in:
6.6.4
Disclosed:
Sep 7, 2018

CVE-2018-0642 on NVD →

FV Flowplayer Video Player 6.1.2 - 6.6.4 - Cross-Site Scripting

medium

Cross-site scripting vulnerability in FV Flowplayer Video Player 6.1.2 to 6.6.4 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.

CVSS:
6.1
Affected:
6.1.2 – 6.6.4
Fixed in:
6.6.5
Disclosed:
Jul 2, 2018

CVE-2018-0642 on NVD →

FV Flowplayer Video Player <= 6.0.3.3 - Stored Cross-Site Scripting

medium

The FV Flowplayer Video Player plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘page’ parameter in versions up to, and including, 6.0.3.3 due to insufficient input sanitization and output escaping. This makes it possible for attackers to inject arbitrary web scripts in pages that will execute...

CVSS:
5.3
Affected:
up to 6.0.3.3
Fixed in:
6.0.3.4
Disclosed:
Aug 24, 2015

FV Flowplayer Video Player [fv-wordpress-flowplayer] < 6.0.3.4

unknown

Because of this vulnerability, authenticated administrators can store HTML or JS code in plugin configuration values. Upgrade this plugin.

Affected:
up to 6.0.3.4
Fixed in:
6.0.3.4
Disclosed:
Aug 24, 2015

FV Flowplayer Video Player [fv-wordpress-flowplayer] < 6.0.3.4

unknown

The FV Flowplayer Video Player plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘page’ parameter in versions up to, and including, 6.0.3.3 due to insufficient input sanitization and output escaping. This makes it possible for attackers to inject arbitrary web scripts in pages that will execute...

Affected:
up to 6.0.3.4
Fixed in:
6.0.3.4
Disclosed:
Aug 24, 2015

FV Flowplayer Video Player [fv-wordpress-flowplayer] < 1.2.12

unknown

[en] Cross-site scripting (XSS) vulnerability in view/frontend-head.php in the Flowplayer plugin before 1.2.12 for WordPress allows remote attackers to inject arbitrary web script or HTML via the URI.

Affected:
up to 1.2.12
Fixed in:
1.2.12
Disclosed:
Nov 29, 2011

CVE-2011-4568 on NVD →

FV Flowplayer Video Player <= 1.2.11 - Cross-Site Scripting

medium

Cross-site scripting (XSS) vulnerability in view/frontend-head.php in the Flowplayer plugin before 1.2.12 for WordPress allows remote attackers to inject arbitrary web script or HTML via the URI.

CVSS:
6.1
Affected:
up to 1.2.11
Fixed in:
1.2.12
Disclosed:
Jul 22, 2011

CVE-2011-4568 on NVD →

FV Flowplayer Video Player [fv-wordpress-flowplayer] < 6.0.3.4

unknown

The FV Flowplayer Video Player WordPress plugin was affected by an Authenticated Stored Cross-Site Scripting (XSS) security vulnerability.

Affected:
up to 6.0.3.4
Fixed in:
6.0.3.4

FV Flowplayer Video Player [fv-wordpress-flowplayer] < 7.2.1.727

unknown

The FV Flowplayer Video Player WordPress plugin was affected by an Authenticated Cross-Site Scripting (XSS) security vulnerability.

Affected:
up to 7.2.1.727
Fixed in:
7.2.1.727

FV Flowplayer Video Player [fv-wordpress-flowplayer] < 7.3.15.727

unknown

Changelog states: Security - fix for email subscription CSV export capability available to guest users

Affected:
up to 7.3.15.727
Fixed in:
7.3.15.727

FV Flowplayer Video Player [fv-wordpress-flowplayer] < 7.5.3.727

unknown

The plugin does not escape or validate the player_id parameter before outputting back in the Stats page in the admin dashboard, leading to a Reflected Cross-Site Scripting issue which will be executed in the context of a logged in administrator

Affected:
up to 7.5.3.727
Fixed in:
7.5.3.727

Protect your WordPress site

Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.

Scan your site free

← Back to the vulnerability database