Multiple Plugins <= (Various Versions) - Authenticated (Contributor+) Stored DOM-Based Cross-Site Scripting via FancyBox JavaScript Library
FV Flowplayer Video Player
Minimum safe version
7.5.48.7212
Update to 7.5.48.7212 or later to address 33 fixable vulnerabilities
CVE-2024-6338
CVE-2024-35631
CVE-2024-32955
CVE-2024-32078
CVE-2024-22299
CVE-2024-29122
CVE-2023-4520
FV Flowplayer Video Player <= 7.5.37.7212 - Insufficient Input Validation to Unauthenticated Stored Cross-Site Scripting and Arbitrary Usermeta Update
FV Flowplayer Video Player <= 6.0.3.3 - Authenticated Stored Cross-Site Scripting (XSS)
FV Flowplayer Video Player <= 7.2.0.727 - Authenticated Cross-Site Scripting (XSS)
FV Flowplayer Video Player <= 7.3.14.727 - CSV Export
FV Flowplayer Video Player < 7.5.3.727 - Reflected Cross-Site Scripting
CVE-2023-30499
CVE-2023-25066
FV Flowplayer Video Player <= 6.0.3.3 - Stored Cross-Site Scripting
FV Flowplayer Video Player <= 7.2.0.727 - Reflected Cross-Site Scripting
FV Flowplayer Video Player <= 7.3.14.727 - Unauthenticated SQL Injection
FV Flowplayer Video Player <= 7.3.14.727 - Sensitive Data Exposure
WordPress Flowplayer Plugin <= 6.0.3.3 - Stored Cross Site Scripting
WordPress FV Flowplayer Video Player plugin <= 7.2.0.727 - Authenticated Cross-Site Scripting (XSS) vulnerability
WordPress FV Flowplayer Video Player plugin <= 7.3.13.727 - Unauthenticated Stored Cross-Site Scripting (XSS) vulnerability
WordPress FV Flowplayer Video Player plugin <= 7.3.14.727 - SQL Injection (SQLi) vulnerability
WordPress FV Flowplayer Video Player plugin <= 7.3.14.727 - CSV Export vulnerability
WordPress FV Flowplayer Video Player plugin <= 7.3.18.727 - SQL Injection (SQLi) vulnerability
CVE-2022-25613
CVE-2022-25607
CVE-2011-4568
WordPress FV Flowplayer Video Player plugin <=6.6.4 - Cross-Site Scripting (XSS) vulnerability
CVE-2019-13573
CVE-2019-14801
CVE-2019-14799
CVE-2019-14800
CVE-2020-35748
CVE-2021-39350