CVE-2019-14800: Infoleak
The FV Flowplayer Video Player plugin before 7.3.15.727 for WordPress allows guests to obtain the email subscription list in CSV format via the wp-admin/admin-post.php?page=fvplayer&fv-email-export=1 URI.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2019-14800?
CVE-2019-14800 is a vulnerability in the FV Flowplayer Video Player plugin for WordPress that allows guests to obtain the email subscription list in CSV format.
How severe is CVE-2019-14800?
CVE-2019-14800 has a severity rating of 5.3, which is considered medium.
What software is affected by CVE-2019-14800?
The FV Flowplayer Video Player plugin before version 7.3.15.727 for WordPress is affected by CVE-2019-14800.
How can I fix CVE-2019-14800?
To fix CVE-2019-14800, update the FV Flowplayer Video Player plugin to version 7.3.15.727 or higher.
Where can I find more information about CVE-2019-14800?
You can find more information about CVE-2019-14800 at the following references: [WordPress.org Plugin Page](https://wordpress.org/plugins/fv-wordpress-flowplayer/#developers), [Plugin Vulnerabilities](https://www.pluginvulnerabilities.com/2019/05/15/information-disclosure-vulnerability-in-fv-player-fv-flowplayer-video-player/).