CVE-2019-14800

MEDIUM

FV Flowplayer Video Player < 7.3.15.727 - Unauthenticated Email Subscription List Exposure via CSV Export

Title source: llm
STIX 2.1

Description

The FV Flowplayer Video Player plugin before 7.3.15.727 for WordPress allows guests to obtain the email subscription list in CSV format via the wp-admin/admin-post.php?page=fvplayer&fv-email-export=1 URI.

Scores

CVSS v3 5.3
EPSS 0.0152
EPSS Percentile 71.4%
Attack Vector NETWORK
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N

Details

CWE
CWE-200
Status published
Products (1)
foliovision/fv_flowplayer_video_player < 7.3.15.727
Published Aug 15, 2019
Tracked Since Feb 18, 2026