Information Disclosure in FV Flowplayer Video Player for WordPress
CVE-2019-14800
5.3MEDIUM
What is CVE-2019-14800?
The FV Flowplayer Video Player plugin for WordPress is vulnerable to information disclosure, allowing unauthorized users to access sensitive data. Specifically, guests can exploit the plugin to download the email subscription list in CSV format by accessing a specific URI, potentially compromising the privacy of users' email information. It is critical for administrators of affected versions to update to 7.3.15.727 or later to mitigate this security risk.