CVE-2022-25607: WordPress FV Flowplayer Video Player plugin <= 7.5.15.727 - SQL Injection (SQLi) vulnerability
Published Mar 18, 2022
·Updated
Authenticated (author or higher user role) SQL Injection (SQLi) vulnerability discovered in FV Flowplayer Video Player WordPress plugin (versions <= 7.5.15.727).
Affected Software
1 affected component
FolioVision Fv Flowplayer Video Player Wordpress<=7.5.15.727
Remediation
Information
Update to 7.5.18.727 or higher version.
Event History
Mar 18, 2022
CVE Published
via MITRE·06:00 PM
Data Sourced
via MITRE·06:00 PM
RemedyDescriptionSeverityWeakness
Frequently Asked Questions
1
What is the vulnerability ID?
The vulnerability ID is CVE-2022-25607.
2
What is the title of the vulnerability?
The title of the vulnerability is Authenticated (author or higher user role) SQL Injection (SQLi) vulnerability discovered in FV Flowplayer Video Player WordPress plugin.
3
What is the affected software?
The affected software is FV Flowplayer Video Player WordPress plugin (versions <= 7.5.15.727).
4
What is the severity of the vulnerability?
The severity of the vulnerability is high with a severity value of 7.2.
5
How can I fix the vulnerability?
To fix the vulnerability, update the FV Flowplayer Video Player WordPress plugin to version 7.5.15.728 or higher.