First published: Mon Apr 04 2022(Updated: )
Authenticated Persistent Cross-Site Scripting (XSS) vulnerability in FV Flowplayer Video Player (WordPress plugin) versions <= 7.5.18.727 via &fv_wp_flowplayer_field_splash parameter.
Credit: audit@patchstack.com
Affected Software | Affected Version | How to fix |
---|---|---|
Flowplayer | <=7.5.18.727 |
Update to 7.5.19.727 or higher version.
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID is CVE-2022-25613.
The title of the vulnerability is Authenticated Persistent Cross-Site Scripting (XSS) vulnerability in FV Flowplayer Video Player (WordPress plugin) versions <= 7.5.18.727.
The severity of CVE-2022-25613 is medium. The severity value is 5.4.
FV Flowplayer Video Player (WordPress plugin) versions <= 7.5.18.727 are affected by the vulnerability.
To fix the vulnerability, update FV Flowplayer Video Player plugin to version 7.5.19 or later.