First published: Thu Aug 15 2019(Updated: )
The FV Flowplayer Video Player plugin before 7.3.15.727 for WordPress allows guests to obtain the email subscription list in CSV format via the wp-admin/admin-post.php?page=fvplayer&fv-email-export=1 URI.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Flowplayer | <7.3.15.727 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2019-14800 is a vulnerability in the FV Flowplayer Video Player plugin for WordPress that allows guests to obtain the email subscription list in CSV format.
CVE-2019-14800 has a severity rating of 5.3, which is considered medium.
The FV Flowplayer Video Player plugin before version 7.3.15.727 for WordPress is affected by CVE-2019-14800.
To fix CVE-2019-14800, update the FV Flowplayer Video Player plugin to version 7.3.15.727 or higher.
You can find more information about CVE-2019-14800 at the following references: [WordPress.org Plugin Page](https://wordpress.org/plugins/fv-wordpress-flowplayer/#developers), [Plugin Vulnerabilities](https://www.pluginvulnerabilities.com/2019/05/15/information-disclosure-vulnerability-in-fv-player-fv-flowplayer-video-player/).