plugin

Fwduvp Vulnerabilities

6 known security issues reported for the Fwduvp WordPress plugin. Most recent disclosed Sep 9, 2025.

2 high 1 medium

Running Fwduvp on your site? Check whether your installed version is affected.

Scan your site free

Ultimate Video Player [fwduvp] <= 10.1 (unfixed)

unknown

[en] Server-Side Request Forgery (SSRF) vulnerability in FWDesign Ultimate Video Player allows Server Side Request Forgery. This issue affects Ultimate Video Player: from n/a through 10.1.

Affected:
up to 10.1
Fix:
No patched version reported
Disclosed:
Sep 9, 2025

CVE-2025-49430 on NVD →

Ultimate Video Player <= 10.1 - Missing Authorization

medium

The Ultimate Video Player WordPress & WooCommerce Plugin plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in all versions up to, and including, 10.1. This makes it possible for unauthenticated attackers to perform an unauthorized action.

CVSS:
5.3
Affected:
up to 10.1
Fix:
No patched version reported
Disclosed:
Aug 15, 2025

CVE-2025-49432 on NVD →

Ultimate Video Player [fwduvp] <= 10.1 (unfixed)

unknown

[en] Missing Authorization vulnerability in FWDesign Ultimate Video Player allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Ultimate Video Player: from n/a through 10.1.

Affected:
up to 10.1
Fix:
No patched version reported
Disclosed:
Aug 15, 2025

CVE-2025-49432 on NVD →

Ultimate Video Player WordPress & WooCommerce Plugin <= 10.1 - Unauthenticated Server-Side Request Forgery

high

The Ultimate Video Player WordPress & WooCommerce Plugin plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 10.1. This makes it possible for unauthenticated attackers to make web requests to arbitrary locations originating from the web application which can be used t...

CVSS:
7.2
Affected:
up to 10.1
Fix:
No patched version reported
Disclosed:
Jul 10, 2025

CVE-2025-49430 on NVD →

Ultimate Video Player [fwduvp] <= 10.0 (unfixed)

unknown

[en] The Ultimate Video Player WordPress & WooCommerce Plugin plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 10.0 via the content/downloader.php file. This makes it possible for unauthenticated attackers to read the contents of arbitrary files on the server, which can co...

Affected:
up to 10.0
Fix:
No patched version reported
Disclosed:
Mar 7, 2025

CVE-2024-10804 on NVD →

Ultimate Video Player <= 10.0 - Unauthenticated Arbitrary File Download

high

The Ultimate Video Player WordPress & WooCommerce Plugin plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 10.0 via the content/downloader.php file. This makes it possible for unauthenticated attackers to read the contents of arbitrary files on the server, which can contain...

CVSS:
7.5
Affected:
up to 10.0
Fixed in:
10.1
Disclosed:
Mar 6, 2025

CVE-2024-10804 on NVD →

Protect your WordPress site

Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.

Scan your site free

← Back to the vulnerability database