The FV Flowplayer Video Player plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the comment text in all versions up to, and including, 7.5.49.7212 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. Exploitation requires an administrator to have enabled the non-default 'Parse Vimeo and YouTube links' (parse_comments) plugin setting, and requires a submitted comment to be approved by an administrator before the payload is publicly delivered.

Project Subscriptions

Vendors Products
Foliovision Subscribe
Fv Flowplayer Video Player Subscribe
Wordpress Subscribe
Wordpress Subscribe
Advisories

No advisories yet.

Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

Tue, 09 Jun 2026 04:45:00 +0000

Type Values Removed Values Added
First Time appeared Foliovision
Foliovision fv Flowplayer Video Player
Wordpress
Wordpress wordpress
Vendors & Products Foliovision
Foliovision fv Flowplayer Video Player
Wordpress
Wordpress wordpress

Tue, 09 Jun 2026 03:15:00 +0000

Type Values Removed Values Added
Description The FV Flowplayer Video Player plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the comment text in all versions up to, and including, 7.5.49.7212 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. Exploitation requires an administrator to have enabled the non-default 'Parse Vimeo and YouTube links' (parse_comments) plugin setting, and requires a submitted comment to be approved by an administrator before the payload is publicly delivered.
Title FV Flowplayer Video Player <= 7.5.49.7212 - Unauthenticated Stored Cross-Site Scripting via Comment Text
Weaknesses CWE-79
References
Metrics cvssV3_1

{'score': 7.2, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:N'}


Projects

Sign in to view the affected projects.

cve-icon MITRE

Status: PUBLISHED

Assigner: Wordfence

Published:

Updated: 2026-06-09T02:28:48.192Z

Reserved: 2026-04-30T19:21:07.292Z

Link: CVE-2026-7556

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-06-09T03:16:26.583

Modified: 2026-06-09T03:16:26.583

Link: CVE-2026-7556

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-06-09T04:30:42Z

Weaknesses