Cross-Site Scripting Vulnerability in FolioVision FV Flowplayer Video Player
CVE-2026-42695

6.5MEDIUM

Key Information:

Vendor

WordPress

Vendor
CVE Published:
9 October 2026

What is CVE-2026-42695?

An improper neutralization of input during web page generation allows attackers to execute stored cross-site scripting (XSS) attacks in the FolioVision FV Flowplayer Video Player plugin for WordPress. This vulnerability affects versions up to 7.5.54.7212, exposing users to potential data theft and malicious content delivery. It’s crucial for users and website owners to review and update their plugins to mitigate this risk effectively.

Affected Version(s)

FV Flowplayer Video Player 0 <= 7.5.54.7212

References

CVSS V3.1

Score:
6.5
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Supakiad S. (m3ez) | Patchstack Bug Bounty Program
.