What the vulnerability does
01Description
Authenticated (author or higher user role) SQL Injection (SQLi) vulnerability discovered in FV Flowplayer Video Player WordPress plugin (versions <= 7.5.15.727).
CVSS base score
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:L/I:L/A:L
What the vulnerability does
Authenticated (author or higher user role) SQL Injection (SQLi) vulnerability discovered in FV Flowplayer Video Player WordPress plugin (versions <= 7.5.15.727).
Explanation of Vulnerability in Simple Terms
The FV Flowplayer Video Player WordPress plugin version 7.5.15.727 and earlier contains a SQL injection vulnerability in a database query. An attacker with high-level site privileges can inject malicious SQL code to read, modify, or delete database records. The vulnerability affects the plugin's core functionality and may impact other site components due to scope change.
What an attacker can do
Read, modify, or delete database records via SQL injection.
Potential impact on your site
A malicious admin or compromised admin account can extract sensitive data or corrupt your site's database.
Conditions required to exploit
Attacker must have high-level WordPress privileges (administrator or equivalent).
Key dates
External resources
Related vulnerabilities