Ultimate Video Player [fwduvp] <= 10.1 (unfixed)
unknown
[en] Server-Side Request Forgery (SSRF) vulnerability in FWDesign Ultimate Video Player allows Server Side Request Forgery. This issue affects Ultimate Video Player: from n/a through 10.1.
- Affected:
- up to 10.1
- Fix:
- No patched version reported
- Disclosed:
- Sep 9, 2025
CVE-2025-49430 on NVD →
Ultimate Video Player <= 10.1 - Missing Authorization
medium
The Ultimate Video Player WordPress & WooCommerce Plugin plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in all versions up to, and including, 10.1. This makes it possible for unauthenticated attackers to perform an unauthorized action.
- CVSS:
- 5.3
- Affected:
- up to 10.1
- Fix:
- No patched version reported
- Disclosed:
- Aug 15, 2025
CVE-2025-49432 on NVD →
Ultimate Video Player [fwduvp] <= 10.1 (unfixed)
unknown
[en] Missing Authorization vulnerability in FWDesign Ultimate Video Player allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Ultimate Video Player: from n/a through 10.1.
- Affected:
- up to 10.1
- Fix:
- No patched version reported
- Disclosed:
- Aug 15, 2025
CVE-2025-49432 on NVD →
Ultimate Video Player WordPress & WooCommerce Plugin <= 10.1 - Unauthenticated Server-Side Request Forgery
high
The Ultimate Video Player WordPress & WooCommerce Plugin plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 10.1. This makes it possible for unauthenticated attackers to make web requests to arbitrary locations originating from the web application which can be used t...
- CVSS:
- 7.2
- Affected:
- up to 10.1
- Fix:
- No patched version reported
- Disclosed:
- Jul 10, 2025
CVE-2025-49430 on NVD →
Ultimate Video Player [fwduvp] <= 10.0 (unfixed)
unknown
[en] The Ultimate Video Player WordPress & WooCommerce Plugin plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 10.0 via the content/downloader.php file. This makes it possible for unauthenticated attackers to read the contents of arbitrary files on the server, which can co...
- Affected:
- up to 10.0
- Fix:
- No patched version reported
- Disclosed:
- Mar 7, 2025
CVE-2024-10804 on NVD →
Ultimate Video Player <= 10.0 - Unauthenticated Arbitrary File Download
high
The Ultimate Video Player WordPress & WooCommerce Plugin plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 10.0 via the content/downloader.php file. This makes it possible for unauthenticated attackers to read the contents of arbitrary files on the server, which can contain...
- CVSS:
- 7.5
- Affected:
- up to 10.0
- Fixed in:
- 10.1
- Disclosed:
- Mar 6, 2025
CVE-2024-10804 on NVD →
Protect your WordPress site
Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.
Scan your site free
← Back to the vulnerability database