Junglewise Threat Intelligence

CVE-2026-7556: FolioVision FV Flowplayer Video Player Stored XSS in comments

CVE-2026-7556 · Severity: high · CVSS 7.2 · Published 2026-06-09

Technologies: FolioVision FV Flowplayer Video Player. Vendors: FolioVision.

Executive brief

The FV Flowplayer Video Player plugin for WordPress, which is used to embed and manage video content, contains a security flaw that allows attackers to inject malicious scripts into website comments. If an administrator has enabled the 'Parse Vimeo and YouTube links' setting, these scripts can execute in the browsers of other visitors once the comment is approved. This could lead to unauthorized actions being performed on behalf of users or the theft of sensitive session information.

Technical details

The FV Flowplayer Video Player plugin for WordPress is vulnerable to Stored Cross-Site Scripting (XSS) via the comment text in all versions up to, and including, 7.5.49.7212. The root cause is insufficient input sanitization and output escaping within the 'parse_comments' functionality. An unauthenticated attacker can submit a comment containing malicious JavaScript; if the non-default 'Parse Vimeo and YouTube links' setting is enabled and the comment is approved by an administrator, the script will execute in the context of any user viewing the page. This allows for session hijacking or unauthorized browser-side actions. A patch has been released in the plugin's trunk/latest versions.

Affected products

  • FolioVision FV Flowplayer Video Player Up to, and including, 7.5.49.7212

Timeline

  • 2026-06-09: disclosed: Initial public disclosure via NVD and Wordfence

References

Related threats