The FV Flowplayer Video Player WordPress plugin is vulnerable to Reflected Cross-Site Scripting via the player_id parameter found in the ~/view/stats.php file which allows malicious users to inject arbitrary web scripts, in versions 7.5.0.727 - 7.5.2.727.
Vulnerable Product | Search on Vulmon | Subscribe to Product |
---|---|---|
foliovision fv flowplayer video player |