Information Disclosure in FV Flowplayer Video Player for WordPress
CVE-2019-14800

5.3MEDIUM

Key Information:

Vendor
Wordpress
Vendor
CVE Published:
15 August 2019

Summary

The FV Flowplayer Video Player plugin for WordPress is vulnerable to information disclosure, allowing unauthorized users to access sensitive data. Specifically, guests can exploit the plugin to download the email subscription list in CSV format by accessing a specific URI, potentially compromising the privacy of users' email information. It is critical for administrators of affected versions to update to 7.3.15.727 or later to mitigate this security risk.

References

CVSS V3.1

Score:
5.3
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
None
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.