Junglewise Threat Intelligence

CVE-2026-12135: Foliovision FV Flowplayer Video Player Stored XSS in video_player shortcode

CVE-2026-12135 · Severity: medium · CVSS 6.4 · Published 2026-07-01

Technologies: FolioVision FV Flowplayer Video Player. Vendors: FolioVision.

Executive brief

The FV Flowplayer Video Player plugin for WordPress, which is used to embed and manage video content on websites, contains a security flaw. This vulnerability allows users with contributor-level access or higher to inject malicious scripts into website pages. When other users or administrators visit these pages, the scripts can execute, potentially leading to unauthorized actions or data theft.

Technical details

The FV Flowplayer Video Player plugin for WordPress is vulnerable to Stored Cross-Site Scripting (XSS) due to insufficient input sanitization and output escaping on the 'align' attribute within the 'video_player' shortcode. An authenticated attacker with at least contributor-level permissions can exploit this by injecting arbitrary web scripts into a post or page. These scripts will execute in the context of any user's browser who views the affected page. The vulnerability exists in all versions up to and including 7.5.51.7212. A patch has been released in subsequent versions to address the improper neutralization of user-supplied input.

Affected products

  • Foliovision FV Flowplayer Video Player up to, and including, 7.5.51.7212

Timeline

  • 2026-07-01: disclosed
  • 2026-07-01: advisory

References

Related threats