Impact
FV Player 8 for WordPress contains a flaw where the check_mimetype function writes attacker‑supplied remote file content to the public uploads directory before any MIME or extension validation or capability check. The absence of a proper file type validation and the missing permission check for new player creation allows an authenticated user with subscriber‑level access or higher to upload arbitrarily named files that can be executable. The description indicates that successfully exploiting a race condition can lead to remote code execution.
Affected Systems
WordPress sites that use the Foliovision FV Player 8 plugin in any release up to and including version 8.1.7 are affected. The vulnerability is present in all prior versions of the plugin, with the issue fixed starting in release 8.1.8.
Risk and Exploitability
The vulnerability carries a CVSS score of 8.8, placing it in the High severity range. An EPSS score is not available, and the vulnerability is not listed in the CISA KEV catalog. Exploitation requires the attacker to be authenticated as a subscriber or higher and to manipulate the race condition during file upload. Because only authenticated users can trigger the flaw, the likelihood of exploitation in environments where subscriber accounts are widely available remains moderate to high, and successful exploitation can provide full remote execution on the underlying web server.
OpenCVE Enrichment