← WordPress Vulnerabilities
WordPress security by component

FV Flowplayer Video Player

FV Flowplayer Video Player is a WordPress component with 19 published CVE records in this archive. The latest tracked vulnerability was published Jul 01, 2026; the highest CVE/CNA score is 9.8.

Plugin slug: fv-wordpress-flowplayer

CVE-2026-12135: FV Flowplayer Video Player: Cross-site scripting

FV Flowplayer Video Player is affected by cross-site scripting. Exploitation requires at least contributor-level access. Injected script can execute in the affected site's origin when the vulnerable output is viewed. The published affected range is <= 7.5.51.7212.

PublishedJul 01, 2026
Known safe version> 7.5.51.7212
Safe version
Jul 01, 2026 CVE-2026-12135
FV Flowplayer Video Player: Cross-site scripting
FV Flowplayer Video Player is affected by cross-site scripting. Exploitation requires at least contributor-level access. Injected script can execute in the affected site's origin when the vulnerable output is viewed. The published affected range is <= 7.5.51.7212.
> 7.5.51.7212
CVE6.4
NVDPending
Jun 15, 2026 CVE-2026-49773
FV Flowplayer Video Player: Cross-site scripting
FV Flowplayer Video Player is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed. The published affected range is n/a to < 7.5.51.7212.
7.5.51.7212
CVE6.5
NVDPending
Jun 09, 2026 CVE-2026-7556
FV Flowplayer Video Player: Cross-site scripting
FV Flowplayer Video Player is affected by cross-site scripting. The vulnerable path is reachable without authentication. Injected script can execute in the affected site's origin when the vulnerable output is viewed. The published affected range is <= 7.5.49.7212.
> 7.5.49.7212
CVE7.2
NVDPending
Jul 19, 2024 CVE-2024-6338
FV Flowplayer Video Player: SQL injection
FV Flowplayer Video Player is affected by SQL injection. Exploitation requires at least subscriber-level access. A successful request can alter database queries and expose or modify WordPress data.
See mitigation notes
CVE8.8
NVDPending
Jun 03, 2024 CVE-2024-35631
FV Flowplayer Video Player: Cross-site scripting
FV Flowplayer Video Player is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE7.1
NVDPending
Apr 24, 2024 CVE-2024-32078
FV Flowplayer Video Player: An open redirect
FV Flowplayer Video Player is affected by an open redirect. Exposure depends on how the affected operation is made reachable by the site. A crafted link can redirect visitors from the trusted site to an attacker-controlled destination.
See mitigation notes
CVE4.1
NVDPending
Apr 24, 2024 CVE-2024-32955
FV Flowplayer Video Player: Server-side request forgery
FV Flowplayer Video Player is affected by server-side request forgery. Exposure depends on how the affected operation is made reachable by the site. The vulnerable server can be induced to make attacker-selected network requests.
See mitigation notes
CVE4.9
NVDPending
Mar 27, 2024 CVE-2024-22299
FV Flowplayer Video Player: Cross-site scripting
FV Flowplayer Video Player is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE7.1
NVDPending
Mar 19, 2024 CVE-2024-29122
FV Flowplayer Video Player: Cross-site scripting
FV Flowplayer Video Player is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE6.5
NVDPending
Aug 25, 2023 CVE-2023-4520
FV Flowplayer Video Player: Cross-site scripting
FV Flowplayer Video Player is affected by cross-site scripting. The vulnerable path is reachable without authentication. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE5.4
NVD6.1
Aug 18, 2023 CVE-2023-30499
Fv Wordpress Flowplayer: Cross-site scripting
Fv Wordpress Flowplayer is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE7.1
NVD6.1
Feb 14, 2023 CVE-2023-25066
Fv Wordpress Flowplayer: Cross-site request forgery
Fv Wordpress Flowplayer is affected by cross-site request forgery. Exposure depends on how the affected operation is made reachable by the site. Exploitation relies on a signed-in privileged user submitting an attacker-controlled request.
See mitigation notes
CVE4.3
NVD8.8
Apr 04, 2022 CVE-2022-25613
Fv Wordpress Flowplayer: Cross-site scripting
Fv Wordpress Flowplayer is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE4.1
NVD5.4
Mar 18, 2022 CVE-2022-25607
Fv Wordpress Flowplayer: SQL injection
Fv Wordpress Flowplayer is affected by SQL injection. Exposure depends on how the affected operation is made reachable by the site. A successful request can alter database queries and expose or modify WordPress data.
See mitigation notes
CVE6.6
NVD7.2
Aug 15, 2019 CVE-2019-14800
Fv Wordpress Flowplayer: A security weakness
Fv Wordpress Flowplayer is affected by a security weakness. Exposure depends on how the affected operation is made reachable by the site. The resulting impact depends on how the affected component exposes the vulnerable operation.
See mitigation notes
CVE5.3
NVD5.3
Aug 09, 2019 CVE-2019-14801
Fv Wordpress Flowplayer: SQL injection
Fv Wordpress Flowplayer is affected by SQL injection. Exposure depends on how the affected operation is made reachable by the site. A successful request can alter database queries and expose or modify WordPress data.
See mitigation notes
CVE9.8
NVD9.8
Aug 09, 2019 CVE-2019-14799
Fv Wordpress Flowplayer: Cross-site scripting
Fv Wordpress Flowplayer is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE6.1
NVD6.1
Jul 17, 2019 CVE-2019-13573
Fv Wordpress Flowplayer: SQL injection
Fv Wordpress Flowplayer is affected by SQL injection. Exposure depends on how the affected operation is made reachable by the site. A successful request can alter database queries and expose or modify WordPress data.
See mitigation notes
CVE9.8
NVD9.8
Sep 07, 2018 CVE-2018-0642
Fv Wordpress Flowplayer: Cross-site scripting
Fv Wordpress Flowplayer is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE6.1
NVD6.1