Entreprise d'experts en Sécurité Informatique : Audits et conseils en cybersécurité
Entreprise française de cybersécurité depuis 2004
☎ 03 60 47 09 81 - info@securiteinfo.com


CVE-2019-14799

Description

The FV Flowplayer Video Player plugin before 7.3.14.727 for WordPress allows email subscription XSS.

POC

Reference

- https://wpvulndb.com/vulnerabilities/9278

- https://www.pluginvulnerabilities.com/2019/05/15/information-disclosure-vulnerability-in-fv-player-fv-flowplayer-video-player/

Github

- https://github.com/20142995/nuclei-templates

- https://github.com/ARPSyndicate/cvemon