Information Disclosure in FV Flowplayer Video Player for WordPress
CVE-2019-14800
5.3MEDIUM
Summary
The FV Flowplayer Video Player plugin for WordPress is vulnerable to information disclosure, allowing unauthorized users to access sensitive data. Specifically, guests can exploit the plugin to download the email subscription list in CSV format by accessing a specific URI, potentially compromising the privacy of users' email information. It is critical for administrators of affected versions to update to 7.3.15.727 or later to mitigate this security risk.
References
CVSS V3.1
Score:
5.3
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
None
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved