WordPress FV Flowplayer Video Player Plugin <= 7.5.32.7212 is vulnerable to Cross Site Scripting (XSS)
Description
Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in FolioVision FV Flowplayer Video Player plugin <= 7.5.32.7212 versions.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Reflected XSS vulnerability in FV Flowplayer Video Player plugin versions ≤7.5.32.7212 allows unauthenticated attackers to inject arbitrary web scripts.
Vulnerability
The FV Flowplayer Video Player WordPress plugin (fv-wordpress-flowplayer) suffers from a reflected Cross-Site Scripting (XSS) vulnerability in versions up to and including 7.5.32.7212. The plugin fails to properly sanitize and escape user-supplied input, allowing an attacker to inject malicious scripts that are reflected back to the user's browser. [1]
Exploitation
An unauthenticated attacker can exploit this vulnerability by crafting a specially crafted URL containing the XSS payload and tricking a victim into clicking it. The attacker does not require any privileged access or user interaction beyond the victim clicking the link. The malicious script executes in the context of the victim's session, with the same origin as the vulnerable WordPress site.
Impact
Successful exploitation allows the attacker to execute arbitrary JavaScript in the victim's browser. This can lead to session hijacking, defacement of the website, redirection to malicious sites, or theft of sensitive information such as login credentials. The impact is limited to the user's browser and the security context of the WordPress site.
Mitigation
The vulnerability is fixed in version 7.5.50.7212, released on 2026-05-04. Users are strongly advised to update to the latest version. No other workarounds are available in the referenced material. [1]
AI Insight generated on May 24, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.
Affected products
2- Range: <= 7.5.32.7212
- Range: n/a
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
1News mentions
0No linked articles in our index yet.