← Back to CVE List

CVE-2021-39350

Published: 2021-10-06T16:15Z
Last Modified: 2025-02-14T19:15Z
Source: MITRE CVE List
License: MITRE-CVE-TOS
The FV Flowplayer Video Player WordPress plugin is vulnerable to Reflected Cross-Site Scripting via the player_id parameter found in the ~/view/stats.php file which allows attackers to inject arbitrary web scripts, in versions 7.5.0.727 - 7.5.2.727. > MITRE Terms of Use apply – see LICENSE‑MITRE.txt