WordPress security by component
FV Flowplayer Video Player
Plugin description
FV Flowplayer Video Player is a WordPress component with 19 published CVE records in this archive. The latest tracked vulnerability was published Jul 01, 2026; the highest CVE/CNA score is 9.8.
Plugin slug:
fv-wordpress-flowplayerLatest vulnerability
CVE-2026-12135: FV Flowplayer Video Player: Cross-site scripting
FV Flowplayer Video Player is affected by cross-site scripting. Exploitation requires at least contributor-level access. Injected script can execute in the affected site's origin when the vulnerable output is viewed. The published affected range is <= 7.5.51.7212.
| Safe version |
|
||
|---|---|---|---|
| Jul 01, 2026 |
CVE-2026-12135
FV Flowplayer Video Player: Cross-site scripting
FV Flowplayer Video Player is affected by cross-site scripting. Exploitation requires at least contributor-level access. Injected script can execute in the affected site's origin when the vulnerable output is viewed. The published affected range is <= 7.5.51.7212.
|
> 7.5.51.7212 |
CVE6.4
NVDPending
|
| Jun 15, 2026 |
CVE-2026-49773
FV Flowplayer Video Player: Cross-site scripting
FV Flowplayer Video Player is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed. The published affected range is n/a to < 7.5.51.7212.
|
7.5.51.7212 |
CVE6.5
NVDPending
|
| Jun 09, 2026 |
CVE-2026-7556
FV Flowplayer Video Player: Cross-site scripting
FV Flowplayer Video Player is affected by cross-site scripting. The vulnerable path is reachable without authentication. Injected script can execute in the affected site's origin when the vulnerable output is viewed. The published affected range is <= 7.5.49.7212.
|
> 7.5.49.7212 |
CVE7.2
NVDPending
|
| Jul 19, 2024 |
CVE-2024-6338
FV Flowplayer Video Player: SQL injection
FV Flowplayer Video Player is affected by SQL injection. Exploitation requires at least subscriber-level access. A successful request can alter database queries and expose or modify WordPress data.
|
See mitigation notes |
CVE8.8
NVDPending
|
| Jun 03, 2024 |
CVE-2024-35631
FV Flowplayer Video Player: Cross-site scripting
FV Flowplayer Video Player is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
|
See mitigation notes |
CVE7.1
NVDPending
|
| Apr 24, 2024 |
CVE-2024-32078
FV Flowplayer Video Player: An open redirect
FV Flowplayer Video Player is affected by an open redirect. Exposure depends on how the affected operation is made reachable by the site. A crafted link can redirect visitors from the trusted site to an attacker-controlled destination.
|
See mitigation notes |
CVE4.1
NVDPending
|
| Apr 24, 2024 |
CVE-2024-32955
FV Flowplayer Video Player: Server-side request forgery
FV Flowplayer Video Player is affected by server-side request forgery. Exposure depends on how the affected operation is made reachable by the site. The vulnerable server can be induced to make attacker-selected network requests.
|
See mitigation notes |
CVE4.9
NVDPending
|
| Mar 27, 2024 |
CVE-2024-22299
FV Flowplayer Video Player: Cross-site scripting
FV Flowplayer Video Player is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
|
See mitigation notes |
CVE7.1
NVDPending
|
| Mar 19, 2024 |
CVE-2024-29122
FV Flowplayer Video Player: Cross-site scripting
FV Flowplayer Video Player is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
|
See mitigation notes |
CVE6.5
NVDPending
|
| Aug 25, 2023 |
CVE-2023-4520
FV Flowplayer Video Player: Cross-site scripting
FV Flowplayer Video Player is affected by cross-site scripting. The vulnerable path is reachable without authentication. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
|
See mitigation notes |
CVE5.4
NVD6.1
|
| Aug 18, 2023 |
CVE-2023-30499
Fv Wordpress Flowplayer: Cross-site scripting
Fv Wordpress Flowplayer is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
|
See mitigation notes |
CVE7.1
NVD6.1
|
| Feb 14, 2023 |
CVE-2023-25066
Fv Wordpress Flowplayer: Cross-site request forgery
Fv Wordpress Flowplayer is affected by cross-site request forgery. Exposure depends on how the affected operation is made reachable by the site. Exploitation relies on a signed-in privileged user submitting an attacker-controlled request.
|
See mitigation notes |
CVE4.3
NVD8.8
|
| Apr 04, 2022 |
CVE-2022-25613
Fv Wordpress Flowplayer: Cross-site scripting
Fv Wordpress Flowplayer is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
|
See mitigation notes |
CVE4.1
NVD5.4
|
| Mar 18, 2022 |
CVE-2022-25607
Fv Wordpress Flowplayer: SQL injection
Fv Wordpress Flowplayer is affected by SQL injection. Exposure depends on how the affected operation is made reachable by the site. A successful request can alter database queries and expose or modify WordPress data.
|
See mitigation notes |
CVE6.6
NVD7.2
|
| Aug 15, 2019 |
CVE-2019-14800
Fv Wordpress Flowplayer: A security weakness
Fv Wordpress Flowplayer is affected by a security weakness. Exposure depends on how the affected operation is made reachable by the site. The resulting impact depends on how the affected component exposes the vulnerable operation.
|
See mitigation notes |
CVE5.3
NVD5.3
|
| Aug 09, 2019 |
CVE-2019-14801
Fv Wordpress Flowplayer: SQL injection
Fv Wordpress Flowplayer is affected by SQL injection. Exposure depends on how the affected operation is made reachable by the site. A successful request can alter database queries and expose or modify WordPress data.
|
See mitigation notes |
CVE9.8
NVD9.8
|
| Aug 09, 2019 |
CVE-2019-14799
Fv Wordpress Flowplayer: Cross-site scripting
Fv Wordpress Flowplayer is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
|
See mitigation notes |
CVE6.1
NVD6.1
|
| Jul 17, 2019 |
CVE-2019-13573
Fv Wordpress Flowplayer: SQL injection
Fv Wordpress Flowplayer is affected by SQL injection. Exposure depends on how the affected operation is made reachable by the site. A successful request can alter database queries and expose or modify WordPress data.
|
See mitigation notes |
CVE9.8
NVD9.8
|
| Sep 07, 2018 |
CVE-2018-0642
Fv Wordpress Flowplayer: Cross-site scripting
Fv Wordpress Flowplayer is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
|
See mitigation notes |
CVE6.1
NVD6.1
|