First published: Fri Mar 18 2022(Updated: )
Authenticated (author or higher user role) SQL Injection (SQLi) vulnerability discovered in FV Flowplayer Video Player WordPress plugin (versions <= 7.5.15.727).
Credit: audit@patchstack.com
Affected Software | Affected Version | How to fix |
---|---|---|
Flowplayer | <=7.5.15.727 |
Update to 7.5.18.727 or higher version.
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID is CVE-2022-25607.
The title of the vulnerability is Authenticated (author or higher user role) SQL Injection (SQLi) vulnerability discovered in FV Flowplayer Video Player WordPress plugin.
The affected software is FV Flowplayer Video Player WordPress plugin (versions <= 7.5.15.727).
The severity of the vulnerability is high with a severity value of 7.2.
To fix the vulnerability, update the FV Flowplayer Video Player WordPress plugin to version 7.5.15.728 or higher.