Sceawere
Vulnerability Detail
CVE-2026-97630UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV
FV Flowplayer Stored XSS
Vulnerability Metadata
- Severity
- Medium
- Score / CVSS
- 6.4
- Creation Date
- 3h ago
- Vendor
- foliovision
- Product
- FV Flowplayer Video Player
- Attack Type
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
- Vector String
- CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N
- Attack Complexity
- LOW
Narrative and Response
Description
The FV Flowplayer Video Player plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Unquoted popup Shortcode Attribute in all versions up to, and including, 7.5.54.7212 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with subscriber-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. Successful exploitation requires the profile_videos_enable_bio option to be enabled, as script execution occurs on the author bio/archive page where the profile-video shortcode is rendered.
Executive Summary
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Technical Details
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Mitigations
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
References
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Additional Metadata
{
"score": "6.4",
"pubDate": "2026-10-10T05:16:40.690Z",
"pubdate": "2026-10-10T05:16:40.690Z",
"executiveSummary": "The FV Flowplayer Video Player plugin for WordPress is susceptible to a Stored Cross-Site Scripting (XSS) vulnerability due to improper input sanitization and output escaping. This vulnerability resides in the processing of the 'popup' shortcode attribute within the profile video functionality. Successful exploitation allows authenticated users with at least subscriber-level privileges to inject malicious JavaScript into author bio or archive pages. When a victim views these pages, the injected script executes within the context of the user's browser session. The attack requires the 'profile_videos_enable_bio' option to be enabled within the plugin configuration. The potential impact includes session hijacking, unauthorized actions performed on behalf of an authenticated user, and the manipulation of site content or redirection of site visitors. Given that the payload is stored persistently, it poses a significant risk for administrative account compromise if an administrator views the affected author bio pages.",
"technicalDetails": "The vulnerability originates from the plugin's failure to adequately sanitize the 'popup' attribute provided within the profile-video shortcode before rendering it on the front end. The root cause is categorized as an improper neutralization of input during web page generation, leading to an XSS condition. Specifically, the plugin does not enforce strict validation or output escaping for this attribute, allowing an attacker to inject arbitrary HTML tags and script elements.\nThe attack vector requires the target WordPress installation to have the 'profile_videos_enable_bio' option enabled. An attacker with subscriber-level permissions, or any higher privilege level, can author or edit their user profile information, or leverage a post/page where they can insert shortcodes if permitted. By embedding the 'profile-video' shortcode with a crafted 'popup' attribute containing a malicious script payload (e.g., <script>alert(document.cookie)</script>), the attacker causes the payload to be saved into the WordPress database as part of the page or profile metadata.\nWhen a user, such as a site administrator or another visitor, requests the page where the shortcode is rendered—specifically the author bio or archive page—the plugin retrieves the unsanitized input from the database and inserts it directly into the HTML markup of the response. Because the application fails to perform context-aware output encoding (such as converting special characters like '<', '>', and '\"' into HTML entities), the browser interprets the injected payload as executable code rather than plain text. Consequently, the browser executes the script in the security context of the vulnerable WordPress site.\nThe vulnerability affects all versions of the FV Flowplayer Video Player plugin up to and including 7.5.54.7212. The scope of impact is limited to the WordPress front-end where the shortcode is parsed. Post-exploitation, an attacker can steal session cookies, perform unauthorized administrative actions if the victim is an administrator, or engage in malicious redirection, thereby compromising the integrity and confidentiality of the session."
}