Description
The FV Flowplayer Video Player plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Unquoted popup Shortcode Attribute in all versions up to, and including, 7.5.54.7212 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with subscriber-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. Successful exploitation requires the profile_videos_enable_bio option to be enabled, as script execution occurs on the author bio/archive page where the profile-video shortcode is rendered.
Published: 2026-10-10
Score: 6.4 Medium
EPSS: n/a
KEV: No
Impact: Stored Cross‑Site Scripting
Action: Apply Patch
AI Analysis

Impact

The FV Flowplayer Video Player plugin for WordPress contains a stored XSS flaw that appears when an authenticated user with subscriber or higher privileges submits a shortcode containing an unquoted popup attribute. The plugin does not properly escape or validate this attribute before it is rendered in the author bio or archive page. An attacker can inject arbitrary JavaScript that will execute automatically for anyone viewing the affected page, potentially allowing session hijacking, data theft, or redirection to malicious sites. The vulnerability is limited to authenticated users who can modify content, but because the injected script runs on every visit to the author's page, the impact extends to all site visitors. The flaw is identified as CWE‑79.

Affected Systems

All WordPress installations that use the Foliovision FV Flowplayer Video Player plugin up to and including version 7.5.54.7212. Any site that has the plugin installed and the profile_videos_enable_bio option active is potentially vulnerable. Subscriptions of the subscriber level or higher provide the necessary access to inject the malicious shortcode.

Risk and Exploitability

The CVSS score of 6.4 classifies the vulnerability as moderate severity, and its EPSS score is not available, indicating no publicly known exploitation frequency data. The weakness is not listed in the CISA KEV catalog. Successful exploitation requires the attacker to be logged in with subscriber or higher privileges and the profile_videos_enable_bio option enabled; the attacker can then craft a shortcode that contains an unquoted attribute, which will be stored in the database and reflected in the author bio page. Because the script runs automatically for each visitor, a single authenticated user can compromise all users who view that page.

Generated by OpenCVE AI on October 10, 2026 at 05:26 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Update FV Flowplayer Video Player to the latest release that includes the XSS fix.
  • If an immediate update is not possible, disable the profile_videos_enable_bio option to prevent the profile‑video shortcode from rendering on author bio/archive pages.
  • As a temporary workaround, ensure that any shortcode attributes containing URLs or script content are quoted or sanitized before being stored or output.

Generated by OpenCVE AI on October 10, 2026 at 05:26 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sat, 10 Oct 2026 04:30:00 +0000

Type Values Removed Values Added
Description The FV Flowplayer Video Player plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Unquoted popup Shortcode Attribute in all versions up to, and including, 7.5.54.7212 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with subscriber-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. Successful exploitation requires the profile_videos_enable_bio option to be enabled, as script execution occurs on the author bio/archive page where the profile-video shortcode is rendered.
Title FV Flowplayer Video Player <= 7.5.54.7212 - Authenticated (Subscriber+) Stored Cross-Site Scripting via Unquoted popup Shortcode Attribute
Weaknesses CWE-79
References
Metrics cvssV3_1

{'score': 6.4, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: Wordfence

Published:

Updated: 2026-10-10T04:26:44.819Z

Reserved: 2026-09-24T16:51:39.432Z

Link: CVE-2026-97630

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-10-10T05:16:40.690

Modified: 2026-10-10T05:16:40.690

Link: CVE-2026-97630

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-10T05:30:09Z

Weaknesses
  • CWE-79

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')