VYPR
Unrated severityNVD Advisory· Published Feb 14, 2023· Updated Apr 28, 2026

WordPress FV Flowplayer Video Player Plugin <= 7.5.30.7212 is vulnerable to Cross Site Request Forgery (CSRF)

CVE-2023-25066

Description

Cross-Site Request Forgery (CSRF) vulnerability in FolioVision FV Flowplayer Video Player plugin <= 7.5.30.7212 versions.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Cross-Site Request Forgery (CSRF) vulnerability in FV Flowplayer Video Player plugin for WordPress versions up to 7.5.30.7212 allows attackers to perform unauthorized actions.

Vulnerability

A Cross-Site Request Forgery (CSRF) vulnerability exists in the FV Flowplayer Video Player plugin for WordPress (fv-wordpress-flowplayer) in versions up to and including 7.5.30.7212. The plugin fails to properly validate or enforce CSRF tokens on certain administrative actions, allowing an attacker to trick a logged-in administrator into executing unintended requests.

Exploitation

An attacker must craft a malicious link or page that, when visited by an authenticated WordPress administrator with the plugin installed, triggers a forged request to the plugin's administrative endpoints. No additional authentication is required beyond the victim's existing session. The attacker does not need direct network access to the target site; the victim's browser performs the request automatically.

Impact

Successful exploitation enables the attacker to perform state-changing operations on the plugin's settings or configuration without the administrator's consent. Depending on the plugin's capabilities, this could include modifying video player options, adding or deleting video sources, or altering other plugin-specific data. The attacker does not gain direct code execution but can manipulate the plugin's behavior.

Mitigation

The vulnerability is fixed in version 7.5.50.7212 of the FV Flowplayer Video Player plugin, as indicated by the plugin's update history [1]. Users should update to this version or later. No workarounds are documented; updating is the recommended action.

AI Insight generated on May 24, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.

Affected products

2

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

1

News mentions

0

No linked articles in our index yet.