Sceawere

Vulnerability Detail

CVE-2026-83526UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

FV Player Arbitrary File Upload

Vulnerability Metadata

Severity
High
Score / CVSS
8.8
Creation Date
2h ago
Vendor
foliovision
Product
FV Player 8
Attack Type
CWE-434 Unrestricted Upload of File with Dangerous Type
Vector String
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Attack Complexity
LOW

Narrative and Response

Description

The FV Player 8 plugin for WordPress is vulnerable to Arbitrary File Upload in all versions up to, and including, 8.1.7 via the check_mimetype function. This is due to insufficient file type validation in check_mimetype(), which writes attacker-supplied remote file content to the public uploads directory before any MIME or extension check, combined with a missing capability check on new player creation. This makes it possible for authenticated attackers, with subscriber-level access and above, to upload files that may be executable, which makes remote code execution possible. This requires successfully exploiting a race condition.

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "8.8",
  "pubDate": "2026-10-10T06:16:43.340Z",
  "pubdate": "2026-10-10T06:16:43.340Z",
  "executiveSummary": "The FV Player 8 plugin for WordPress, in versions up to and including 8.1.7, contains a critical arbitrary file upload vulnerability. This vulnerability originates from insufficient validation logic within the check_mimetype() function, which fails to adequately sanitize file uploads before they are persisted to the server's public directory.\nThe flaw allows authenticated users, including those with minimal subscriber-level privileges, to upload potentially executable files to the web server. Because the plugin writes remote file content to the filesystem prior to performing necessary MIME-type or extension verification, an attacker can bypass security controls to facilitate remote code execution (RCE).\nSuccessful exploitation requires the attacker to leverage a race condition during the file upload process. This security defect poses a high risk to the confidentiality, integrity, and availability of the WordPress installation, as it grants attackers the ability to execute arbitrary code within the server environment. Mitigation is imperative to prevent unauthorized system compromise.",
  "technicalDetails": "The vulnerability resides in the check_mimetype() function within the FV Player 8 plugin, which acts as the primary validation mechanism for user-supplied files. The root cause is an improper execution order of operations: the plugin accepts a remote file stream and commits it to the server's public uploads directory before executing any form of security validation, such as checking the file extension or performing a robust MIME-type analysis.\nThe attack flow begins when an authenticated user (possessing subscriber-level privileges or higher) initiates a request to the plugin that triggers the creation of a new player. Due to a missing capability check on the player creation functionality, an attacker can bypass the intended permission restrictions. By sending a crafted request that points to an attacker-controlled remote resource, the plugin fetches the remote file and saves it locally.\nThe exploit relies on a race condition between the time the file is written to the disk and the subsequent (and ultimately futile) check_mimetype() validation. Since the file is already residing in an accessible public directory before the validation logic finishes execution, an attacker can access the uploaded file via a direct HTTP request. If the server is configured to execute scripts (e.g., PHP files), the attacker can achieve remote code execution by uploading a malicious script that the server interprets.\nThe exposure is significant as the vulnerability does not require administrative privileges. Any authenticated user can trigger the logic, creating a broad attack surface for unauthorized entities who have compromised a low-privilege user account. Once the script is successfully uploaded and accessed, the attacker gains the ability to execute arbitrary code with the permissions of the web server user, leading to potential full site takeover, data exfiltration, or lateral movement within the hosting infrastructure. The lack of strict input sanitization coupled with the premature writing of binary data to the filesystem creates an insecure environment where the check_mimetype() function fails its primary duty of protecting the system from malicious file uploads."
}
CVE-2026-83526: FV Player Arbitrary File Upload (HIGH Severity, CVSS: 8.8) | Sceawere