Record summary

CVE-2021-39350 has a selected CVSS score of 6.1 (medium); EIP currently links 1 Nuclei template.

Description

The FV Flowplayer Video Player WordPress plugin is vulnerable to Reflected Cross-Site Scripting via the player_id parameter found in the ~/view/stats.php file which allows attackers to inject arbitrary web scripts, in versions 7.5.0.727 - 7.5.2.727.

Description source: CVE List

Exploitation context

Available material

Nuclei templates
1

CISA SSVC decision

ExploitationNone
AutomatableNo
Technical impactPartial

CISA Coordinator · SSVC 2.0.3 · Evaluated Feb 14, 2025 · Source: CVE List

Affected products and versions

1
ProductSourceVersion rangeStatus
CVE List7.5.0.727 - 7.5.2.727 7.5.2.727affected

Nuclei templates

1
ProjectDiscoveryMEDIUMFV Flowplayer Video Player WordPress plugin - Authenticated Cross-Site ScriptingCVSS 6.1

The FV Flowplayer Video Player WordPress plugin is vulnerable to Reflected Cross-Site Scripting via the player_id parameter found in the ~/view/stats.php file which allows attackers to inject arbitrary web scripts in versions 7.5.0.727 - 7.5.2.727.

Impact

Successful exploitation of this vulnerability could allow an authenticated attacker to execute arbitrary JavaScript code in the context of the affected website, potentially leading to session hijacking, defacement, or theft of sensitive information.

Remediation

Update to the latest version of the FV Flowplayer Video Player WordPress plugin to mitigate this vulnerability.

WeaknessesCWE-79
Authorsgy741
Template tagscve2021cvewpscanwordpressxsswpwp-pluginauthenticatedfoliovisionvuln
CVSS vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
CPE: cpe:2.3:a:foliovision:fv_flowplayer_video_player:*:*:*:*:*:wordpress:*:*

Source: ProjectDiscovery

References

3