Junglewise Threat Intelligence

CVE-2026-49773: Foliovision FV Flowplayer Video Player Subscriber XSS

CVE-2026-49773 · Severity: medium · CVSS 6.5 · Published 2026-06-15

Technologies: FolioVision FV Flowplayer Video Player. Vendors: FolioVision.

Executive brief

The FV Flowplayer Video Player plugin for WordPress is vulnerable to a security flaw that allows users with basic 'Subscriber' accounts to inject malicious scripts into the website. If an administrator or another visitor views the affected content, these scripts could steal login sessions, redirect users to dangerous websites, or deface the site. This could lead to unauthorized access to the website's management area or damage the site's reputation with visitors.

Technical details

A Stored Cross-Site Scripting (XSS) vulnerability exists in the FV Flowplayer Video Player plugin for WordPress in versions prior to 7.5.51.7212. The issue stems from improper neutralization of user-supplied input, allowing an authenticated attacker with Subscriber-level privileges to inject arbitrary web scripts. Exploitation requires a victim (such as a site administrator) to interact with the malicious payload, typically by viewing a page where the script has been stored. Successful exploitation can lead to session hijacking, unauthorized administrative actions, or site defacement. The vulnerability is addressed in version 7.5.51.7212.

Affected products

  • Foliovision FV Flowplayer Video Player < 7.5.51.7212

Timeline

  • 2026-05-04: other: Vulnerability reported by Jakub Herman
  • 2026-06-04: advisory: Patchstack published advisory
  • 2026-06-15: disclosed: CVE published to NVD

References

Related threats