Cross-Site Scripting
17 records63%First: 2011. Latest: 2026.
Plugin security history
The Wordfence Intelligence dataset currently contains 27 vulnerability records associated with FV Flowplayer Video Player, published between 2011 and 2026.
Dataset last synchronized: 2026-08-03 00:31:25 UTC
At a glance
| Year | Records | Relative volume |
|---|---|---|
| 2011 | 1 | |
| 2015 | 1 | |
| 2018 | 2 | |
| 2019 | 6 | |
| 2021 | 2 | |
| 2022 | 2 | |
| 2023 | 3 | |
| 2024 | 7 | |
| 2026 | 3 |
| Severity | Records | Share |
|---|---|---|
| Critical | 3 | 11.1% |
| High | 3 | 11.1% |
| Medium | 21 | 77.8% |
First: 2011. Latest: 2026.
First: 2019. Latest: 2024.
First: 2019. Latest: 2019.
First: 2024. Latest: 2024.
First: 2023. Latest: 2023.
Patch status reflects the latest successfully synchronized source dataset and must be checked against the installed version.
7.5.52.72127.5.50.72127.5.51.72127.5.48.72127.5.47.72127.5.46.72127.5.45.72127.5.44.72127.5.39.72127.5.35.72127.5.31.72127.5.19.7287.5.18.7277.5.3.7277.4.38.7277.3.19.7277.3.14.7277.3.15.7277.2.1.7276.6.56.0.3.41.2.12Ranges are deduplicated by source range record and shown with the associated disclosure and known patched versions.
| Affected range | Vulnerability | Published | Patched version | Severity |
|---|---|---|---|---|
*-7.5.51.7212 | FV Flowplayer Video Player <= 7.5.51.7212 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'video_player' Shortcode | June 30, 2026 | 7.5.52.7212 | Medium |
*-7.5.49.7212 | FV Flowplayer Video Player <= 7.5.49.7212 - Unauthenticated Stored Cross-Site Scripting via Comment Text | June 8, 2026 | 7.5.50.7212 | High |
[*, 7.5.51.7212) | FV Flowplayer Video Player < 7.5.51.7212 - Authenticated (Subscriber+) Stored Cross-Site Scripting | June 4, 2026 | 7.5.51.7212 | Medium |
*-7.5.47.7212 | Multiple Plugins <= (Various Versions) - Authenticated (Contributor+) Stored DOM-Based Cross-Site Scripting via FancyBox JavaScript Library | December 3, 2024 | 7.5.48.7212 | Medium |
*-7.5.46.7212 | FV Player <= 7.5.46.7212 - Authenticated (Subscriber+) SQL Injection via exclude Parameter | July 18, 2024 | 7.5.47.7212 | High |
*-7.5.45.7212 | FV Flowplayer Video Player <= 7.5.45.7212 - Reflected Cross-Site Scripting | May 27, 2024 | 7.5.46.7212 | Medium |
*-7.5.43.7212 | FV Flowplayer Video Player <= 7.5.43.7212 - Authenticated (Subscriber+) Server-side Request Forgery | April 22, 2024 | 7.5.45.7212 | Medium |
*-7.5.44.7212 | FV Flowplayer Video Player <= 7.5.44.7212 - Authenticated (Contributor+) Arbitrary Redirect | April 11, 2024 | 7.5.45.7212 | Medium |
*-7.5.41.7212 | FV Flowplayer Video Player <= 7.5.41.7212 - Reflected Cross-Site Scripting | March 26, 2024 | 7.5.44.7212 | Medium |
*-7.5.41.7212 | FV Flowplayer Video Player <= 7.5.41.7212 - Authenticated (Contributor+) Stored Cross-Site Scripting | March 16, 2024 | 7.5.44.7212 | Medium |
*-7.5.37.7212 | FV Flowplayer Video Player <= 7.5.37.7212 - Insufficient Input Validation to Unauthenticated Stored Cross-Site Scripting and Arbitrary Usermeta Update | August 24, 2023 | 7.5.39.7212 | Medium |
*-7.5.32.7212 | FV Flowplayer Video Player <= 7.5.32.7212 - Reflected Cross-Site Scripting via id | May 3, 2023 | 7.5.35.7212 | Medium |
*-7.5.30.7210 | FV Flowplayer Video Player <= 7.5.30.7210 - Cross-Site Request Forgery | February 2, 2023 | 7.5.31.7212 | Medium |
*-7.5.18.727 | FV Flowplayer Video Player <= 7.5.18.727 - Stored Cross-Site Scripting | April 4, 2022 | 7.5.19.728 | Medium |
*-7.5.15.727 | FV Flowplayer Video Player <= 7.5.15.727 - SQL Injection | March 18, 2022 | 7.5.18.727 | High |
7.5.0.727-7.5.2.727 | FV Flowplayer Video Player 7.5.0.727 - 7.5.2.727 - Reflected Cross-Site Scripting via player_id Parameter | October 5, 2021 | 7.5.3.727 | Medium |
*-7.4.37.727 | FV Flowplayer Video Player <= 7.4.37.727 - Authenticated Stored Cross-Site Scripting | January 15, 2021 | 7.4.38.727 | Medium |
*-7.3.18.727 | FV Flowplayer Video Player <= 7.3.18.727 - SQL Injection | July 11, 2019 | 7.3.19.727 | Critical |
*-7.3.13.727 | FV Flowplayer Video Player <= 7.3.13.727 - Unauthenticated Stored Cross-Site Scripting | May 20, 2019 | 7.3.14.727 | Medium |
[*, 7.3.15.727) | FV Flowplayer Video Player <= 7.3.14.727 - SQL Injection | May 20, 2019 | 7.3.15.727 | Critical |
*-7.3.14.727 | FV Flowplayer Video Player <= 7.3.14.727 - Sensitive Information Exposure | May 20, 2019 | 7.3.15.727 | Medium |
[*, 7.3.15.727) | FV Flowplayer Video Player <= 7.3.14.727 - Unauthenticated SQL Injection | May 16, 2019 | 7.3.15.727 | Critical |
[*, 7.3.15.727) | FV Flowplayer Video Player <= 7.3.14.727 - Sensitive Data Exposure | May 16, 2019 | 7.3.15.727 | Medium |
*-7.2.0.727 | FV Flowplayer Video Player <= 7.2.0.727 - Reflected Cross-Site Scripting | September 21, 2018 | 7.2.1.727 | Medium |
6.1.2-6.6.4 | FV Flowplayer Video Player 6.1.2 - 6.6.4 - Cross-Site Scripting | July 2, 2018 | 6.6.5 | Medium |
Selected source records
Published: June 30, 2026
Published: June 8, 2026
Published: June 4, 2026
Published: December 3, 2024
Published: July 18, 2024
Published: May 27, 2024
Published: April 22, 2024
Published: April 11, 2024
Published: July 11, 2019
Published: May 20, 2019
Published: May 16, 2019
Published: July 18, 2024
Published: March 18, 2022
Published: June 8, 2026
Published: March 16, 2024
Published: January 15, 2021
Running an affected version does not prove that a website was compromised. Suspicious redirects, unknown administrators, injected content, unexpected files or recurring malware may require a manual investigation.
Vulnerability data: Wordfence Intelligence. Analysis and practical guidance: 3Zero Digital.
This page aggregates active Production Feed records. Counts are not software-quality rankings, and an affected version does not prove exploitation or infection. Read the full methodology.