CVE-2022-25613: WordPress FV Flowplayer Video Player plugin <= 7.5.18.727 - Authenticated Persistent Cross-Site Scripting (XSS) vulnerability
Published Apr 4, 2022
·Updated
Authenticated Persistent Cross-Site Scripting (XSS) vulnerability in FV Flowplayer Video Player (WordPress plugin) versions <= 7.5.18.727 via &fvwpflowplayerfieldsplash parameter.
Affected Software
1 affected component
FolioVision Fv Flowplayer Video Player Wordpress<=7.5.18.727
Remediation
Information
Update to 7.5.19.727 or higher version.
Event History
Apr 4, 2022
CVE Published
via MITRE·07:46 PM
Data Sourced
via MITRE·07:46 PM
RemedyDescriptionSeverityWeakness
Frequently Asked Questions
1
What is the vulnerability ID?
The vulnerability ID is CVE-2022-25613.
2
What is the title of the vulnerability?
The title of the vulnerability is Authenticated Persistent Cross-Site Scripting (XSS) vulnerability in FV Flowplayer Video Player (WordPress plugin) versions <= 7.5.18.727.
3
What is the severity of CVE-2022-25613?
The severity of CVE-2022-25613 is medium. The severity value is 5.4.
4
Which software versions are affected by the vulnerability?
FV Flowplayer Video Player (WordPress plugin) versions <= 7.5.18.727 are affected by the vulnerability.
5
How can I fix the Authenticated Persistent Cross-Site Scripting (XSS) vulnerability in FV Flowplayer Video Player?
To fix the vulnerability, update FV Flowplayer Video Player plugin to version 7.5.19 or later.