Description
Unauthenticated Cross Site Scripting (XSS) in FV Player 8 <= 8.1.8 versions.
Published: 2026-10-10
Score: 7.1 High
EPSS: n/a
KEV: No
Impact: Cross Site Scripting (XSS)
Action: Immediate Patch
AI Analysis

Impact

An unauthenticated XSS flaw exists in the WordPress FV Player 8 plugin up to version 8.1.8. Attackers can inject malicious scripts through crafted input that the plugin echoes without proper sanitization, enabling arbitrary client‑side code execution. This flaw permits data theft, phishing, or session hijacking within the user’s browser context, and it is a classic input validation failure (CWE‑79).

Affected Systems

The vulnerability affects installations of FolioVision’s FV Player 8 plugin for WordPress that use the plugin in versions 8.1.8 or earlier. The latest patch (8.1.9 or newer) eliminates the flaw, and only sites using the older versions remain at risk.

Risk and Exploitability

With a CVSS score of 7.1, the flaw poses high severity risks to confidentiality, integrity, and availability. Although EPSS information is unavailable and the vulnerability is not listed in CISA KEV, the threat remains significant because unauthenticated users can deliver the malicious payload via exposed input fields. Once executed, the code runs in the victim’s browser, potentially compromising user sessions and sensitive data.

Generated by OpenCVE AI on October 10, 2026 at 20:21 UTC.

Remediation

Vendor Solution

Update the WordPress FV Player 8 plugin to the latest available version (at least 8.1.9).


OpenCVE Recommended Actions

  • Upgrade the FV Player 8 plugin to version 8.1.9 or newer.
  • Remove any residual files from older plugin versions to prevent fallback to vulnerable code.
  • Perform a comprehensive review of posts, pages, or custom components that displayed plugin output, and sanitize or delete any injected scripts discovered during the audit.

Generated by OpenCVE AI on October 10, 2026 at 20:21 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sat, 10 Oct 2026 19:45:00 +0000

Type Values Removed Values Added
Description Unauthenticated Cross Site Scripting (XSS) in FV Player 8 <= 8.1.8 versions.
Title WordPress FV Player 8 plugin <= 8.1.8 - Cross Site Scripting (XSS) vulnerability
Weaknesses CWE-79
References
Metrics cvssV3_1

{'score': 7.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published:

Updated: 2026-10-10T19:35:10.023Z

Reserved: 2026-04-29T09:05:07.700Z

Link: CVE-2026-42699

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-10-10T20:16:35.560

Modified: 2026-10-10T20:16:35.560

Link: CVE-2026-42699

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-10T20:30:06Z

Weaknesses
  • CWE-79

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')