Executive brief
The FV Flowplayer Video Player plugin for WordPress, which is used to embed and manage video content on websites, contains a security flaw. This vulnerability allows users with contributor-level access or higher to inject malicious scripts into website pages. When other users or administrators visit these pages, the scripts can execute, potentially leading to unauthorized actions or data theft.
Technical details
The FV Flowplayer Video Player plugin for WordPress is vulnerable to Stored Cross-Site Scripting (XSS) due to insufficient input sanitization and output escaping on the 'align' attribute within the 'video_player' shortcode. An authenticated attacker with at least contributor-level permissions can exploit this by injecting arbitrary web scripts into a post or page. These scripts will execute in the context of any user's browser who views the affected page. The vulnerability exists in all versions up to and including 7.5.51.7212. A patch has been released in subsequent versions to address the improper neutralization of user-supplied input.
Affected products
- Foliovision FV Flowplayer Video Player up to, and including, 7.5.51.7212
Timeline
- 2026-07-01: disclosed
- 2026-07-01: advisory
References
- https://plugins.trac.wordpress.org/browser/fv-wordpress-flowplayer/tags/7.5.49.7212/controller/shortcodes.php
- https://plugins.trac.wordpress.org/browser/fv-wordpress-flowplayer/tags/7.5.49.7212/controller/shortcodes.php
- https://plugins.trac.wordpress.org/browser/fv-wordpress-flowplayer/trunk/controller/shortcodes.php
- https://plugins.trac.wordpress.org/browser/fv-wordpress-flowplayer/trunk/controller/shortcodes.php
- https://plugins.trac.wordpress.org/changeset?sfp_email=&sfph_mail=&reponame=&new=3586305%40fv-wordpress-flowplayer%2Ftrunk&old=3557974%40fv-wordpress-flowplayer%2Ftrunk&sfp_email=&sfph_mail=
- https://www.wordfence.com/threat-intel/vulnerabilities/id/d5a3a560-08e6-43b7-b953-4e704eafc49b?source=cve