Impact
An unauthenticated XSS flaw exists in the WordPress FV Player 8 plugin up to version 8.1.8. Attackers can inject malicious scripts through crafted input that the plugin echoes without proper sanitization, enabling arbitrary client‑side code execution. This flaw permits data theft, phishing, or session hijacking within the user’s browser context, and it is a classic input validation failure (CWE‑79).
Affected Systems
The vulnerability affects installations of FolioVision’s FV Player 8 plugin for WordPress that use the plugin in versions 8.1.8 or earlier. The latest patch (8.1.9 or newer) eliminates the flaw, and only sites using the older versions remain at risk.
Risk and Exploitability
With a CVSS score of 7.1, the flaw poses high severity risks to confidentiality, integrity, and availability. Although EPSS information is unavailable and the vulnerability is not listed in CISA KEV, the threat remains significant because unauthenticated users can deliver the malicious payload via exposed input fields. Once executed, the code runs in the victim’s browser, potentially compromising user sessions and sensitive data.
OpenCVE Enrichment