CVE-2026-42699: WordPress FV Player 8 plugin <= 8.1.8 - Cross Site Scripting (XSS) vulnerability
Published Oct 10, 2026
·Updated
Unauthenticated Cross Site Scripting (XSS) in FV Player 8 <= 8.1.8 versions.
Affected Software
1 affected component
FolioVision FV Player 8<=8.1.8
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
WordPress FV Player 8 pluginto a version that resolves this vulnerability.Fixed in 8.1.9
Event History
Oct 10, 2026
CVE Published
via MITRE·07:35 PM
Data Sourced
via MITRE·07:35 PM
RemedyDescriptionSeverityWeakness
Data Sourced
via NVD·08:16 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
Who can exploit this issue?
The vulnerability is unauthenticated, so an attacker does not need a WordPress account or FV Player privileges. Exploitation does require user interaction, as indicated by the UI:R vector.
2
What versions are affected?
FV Player 8 versions up to and including 8.1.8 are affected. The provided information does not identify a fixed version.
3
What is the potential impact?
Successful exploitation can run attacker-supplied script in a victim's browser context. The supplied vector indicates low confidentiality, integrity, and availability impact, with scope changed.