VYPR

FV Player

by WordPress

CVEs (1)

  • CVE-2026-83526HigOct 10, 2026
    risk 0.57cvss 8.8epss —

    The FV Player 8 plugin for WordPress is vulnerable to Arbitrary File Upload in all versions up to, and including, 8.1.7 via the check_mimetype function. This is due to insufficient file type validation in check_mimetype(), which writes attacker-supplied remote file content to…