First published: Fri Aug 09 2019(Updated: )
The FV Flowplayer Video Player plugin before 7.3.14.727 for WordPress allows email subscription XSS.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Flowplayer | <7.3.14.727 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2019-14799 is a vulnerability found in the FV Flowplayer Video Player plugin for WordPress, allowing email subscription XSS.
CVE-2019-14799 has a severity keyword of 'medium' and a severity value of 6.1.
CVE-2019-14799 allows attackers to execute malicious scripts via email subscription XSS.
To fix CVE-2019-14799, update the FV Flowplayer Video Player plugin to version 7.3.14.727 or newer.
Yes, you can find references to CVE-2019-14799 at the following URLs: [1] https://wordpress.org/plugins/fv-wordpress-flowplayer/#developers [2] https://wpvulndb.com/vulnerabilities/9278 [3] https://www.pluginvulnerabilities.com/2019/05/15/information-disclosure-vulnerability-in-fv-player-fv-flowplayer-video-player/