Impact
The FV Flowplayer Video Player plugin for WordPress contains a stored XSS flaw that appears when an authenticated user with subscriber or higher privileges submits a shortcode containing an unquoted popup attribute. The plugin does not properly escape or validate this attribute before it is rendered in the author bio or archive page. An attacker can inject arbitrary JavaScript that will execute automatically for anyone viewing the affected page, potentially allowing session hijacking, data theft, or redirection to malicious sites. The vulnerability is limited to authenticated users who can modify content, but because the injected script runs on every visit to the author's page, the impact extends to all site visitors. The flaw is identified as CWE‑79.
Affected Systems
All WordPress installations that use the Foliovision FV Flowplayer Video Player plugin up to and including version 7.5.54.7212. Any site that has the plugin installed and the profile_videos_enable_bio option active is potentially vulnerable. Subscriptions of the subscriber level or higher provide the necessary access to inject the malicious shortcode.
Risk and Exploitability
The CVSS score of 6.4 classifies the vulnerability as moderate severity, and its EPSS score is not available, indicating no publicly known exploitation frequency data. The weakness is not listed in the CISA KEV catalog. Successful exploitation requires the attacker to be logged in with subscriber or higher privileges and the profile_videos_enable_bio option enabled; the attacker can then craft a shortcode that contains an unquoted attribute, which will be stored in the database and reflected in the author bio page. Because the script runs automatically for each visitor, a single authenticated user can compromise all users who view that page.
OpenCVE Enrichment