CVE-2022-25607 MEDIUM

CVE-2022-25607: WordPress FV Flowplayer Video Player plugin <= 7.5.15.727 - SQL Injection (SQLi) vulnerability

Vendor Foliovision
Product FV Flowplayer Video Player (WordPress plugin)
Weakness CWE-89 · SQLi
Published March 18, 2022
Last update April 28, 2026

CVSS base score

6.6/10
Attack vector Network
Attack complexity Low
Privileges required High
User interaction None
Confidentiality Low
Integrity Low

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:L/I:L/A:L

What the vulnerability does

01Description

Authenticated (author or higher user role) SQL Injection (SQLi) vulnerability discovered in FV Flowplayer Video Player WordPress plugin (versions <= 7.5.15.727).

Explanation of Vulnerability in Simple Terms

02Summary

The FV Flowplayer Video Player WordPress plugin version 7.5.15.727 and earlier contains a SQL injection vulnerability in a database query. An attacker with high-level site privileges can inject malicious SQL code to read, modify, or delete database records. The vulnerability affects the plugin's core functionality and may impact other site components due to scope change.

What an attacker can do

03Attacker Capabilities

Read, modify, or delete database records via SQL injection.

Potential impact on your site

04Site Impact

A malicious admin or compromised admin account can extract sensitive data or corrupt your site's database.

Conditions required to exploit

05Prerequisites

Attacker must have high-level WordPress privileges (administrator or equivalent).

Key dates

06Disclosure timeline

March 18, 2022 CVE published
April 28, 2026 Record updated

Related vulnerabilities

08Related CVE