CVE-2024-32078
WordPress FV Player plugin <= 7.5.44.7212 - Unvalidated Redirects and Forwards vulnerability
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
0Exploited in Wild
-Decision
Descriptions
URL Redirection to Untrusted Site ('Open Redirect') vulnerability in Foliovision FV Flowplayer Video Player.This issue affects FV Flowplayer Video Player: from n/a through 7.5.44.7212.
Vulnerabilidad de redirección de URL a sitio no confiable ("Open Redirect") en Foliovision FV Flowplayer Video Player. Este problema afecta a FV Flowplayer Video Player: desde n/a hasta 7.5.44.7212.
The FV Flowplayer Video Player plugin for WordPress is vulnerable to unauthorized redirects in all versions up to, and including, 7.5.44.7212. This is due to the plugin not restricting contributor and above users from being able to add redirects at the end of videos. This makes it possible for authenticated attackers, with contributor-level access and above, to redirect administrators to arbitrary sites that can be malicious.
CVSS Scores
SSVC
- Decision:Track
Timeline
- 2024-04-10 CVE Reserved
- 2024-04-11 CVE Published
- 2024-04-25 EPSS Updated
- 2024-08-02 CVE Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
- CWE-601: URL Redirection to Untrusted Site ('Open Redirect')
CAPEC
References (1)
URL | Tag | Source |
---|---|---|
https://patchstack.com/database/vulnerability/fv-wordpress-flowplayer/wordpress-fv-player-plugin-7-5-44-7212-unvalidated-redirects-and-forwards-vulnerability?_s_id=cve | Vdb Entry |
URL | Date | SRC |
---|
URL | Date | SRC |
---|
URL | Date | SRC |
---|
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Fv Wordpress Flowplayer Search vendor "Fv Wordpress Flowplayer" | Fv Wordpress Flowplayer Search vendor "Fv Wordpress Flowplayer" for product "Fv Wordpress Flowplayer" | >= 0.0.0.0 <= 7.5.44.7212 Search vendor "Fv Wordpress Flowplayer" for product "Fv Wordpress Flowplayer" and version " >= 0.0.0.0 <= 7.5.44.7212" | en |
Affected
|