The FV Flowplayer Video Player WordPress plugin is vulnerable to Reflected Cross-Site Scripting via the player_id parameter found in the ~/view/stats.php file which allows attackers to inject arbitrary web scripts, in versions 7.5.0.727 - 7.5.2.727.
Metrics
Affected Vendors & Products
References
History
No history.
MITRE
Status: PUBLISHED
Assigner: Wordfence
Published: 2021-10-06T15:21:54.011885Z
Updated: 2024-09-17T00:00:38.536Z
Reserved: 2021-08-20T00:00:00
Link: CVE-2021-39350
Vulnrichment
No data.
NVD
Status : Analyzed
Published: 2021-10-06T16:15:07.427
Modified: 2021-10-14T14:52:12.203
Link: CVE-2021-39350
Redhat
No data.