S4E just found a high-severity finding from top 10 tcp port service scan
PlatformPlansPartners
Resources
ToolsBlogDocs
Sign Up →
medium·Product Based Web Vulnerabilities·Updated Jan 3, 2024

CVE-2021-39350 Scanner

CVE-2021-39350 scanner - Cross-Site Scripting (XSS) vulnerability in FV Flowplayer Video Player plugin for WordPress

Est. Time~10 seconds
Scan TypeSingle Scan
Targetsdomain, ipv4, subdomain
CostFree
3.2k
Times Used
continuous scan runs
5.1k
Continuously Checked
assets under CS
0
Vulnerabilities Found
confirmed findings
References
CVECVE-2021-39350
6.1
CVSSmedium
Exploitable remotely over the internet · no authentication required · user interaction needed.

The FV Flowplayer Video Player WordPress plugin is vulnerable to Reflected Cross-Site Scripting via the player_id parameter found in the ~/view/stats.php file which allows attackers to inject arbitrary web scripts, in versions 7.5.0.727 - 7.5.2.727.

Attack Vector
Network
Privileges Req.
None
User Interaction
Required
Affected
FV Flowplayer Video Playerby FV Flowplayer Video Player
7.5.0.727 - 7.5.2.727 7.5.2.727
Updated Aug 21, 2026View on NVD →
Detail

FV Flowplayer Video Player is a WordPress plugin that allows users to embed and stream videos on their website. This plugin provides a range of customization options and features, including video analytics and responsive design. It is widely used by professionals and amateurs for creating and sharing videos on their WordPress sites. 

However, a critical vulnerability, CVE-2021-39350, has been detected in this plugin between versions 7.5.0.727 and 7.5.2.727. The vulnerability is caused by a lack of input validation on the player_id parameter found in the ~/view/stats.php file. This vulnerability allows attackers to insert malicious scripts into web pages, which in turn can lead to cross-site scripting attacks.

Exploiting this vulnerability can lead to a range of malicious activities, such as stealing sensitive information like passwords, session cookies, and other valuable user data. It can also be used to redirect users to fake or malicious websites, or to perform other actions not authorized by the user. In short, this vulnerability can allow attackers to gain full control over the victim's website and data.

In conclusion, FV Flowplayer Video Player users are urged to take necessary precautions to prevent their sites from being compromised by this vulnerability. By subscribing to pro features at s4e.io, individuals can quickly and efficiently identify and eliminate vulnerabilities present in their digital assets. Don't wait until it's too late – protect your website today.

 

REFERENCES

Solution Advice

To protect against this vulnerability, FV Flowplayer Video Player users are recommended to take the following precautions:

  • Update the plugin to the latest version available, which includes patches for this vulnerability.
  • Consider disabling vulnerable features or limiting access to the ~/view/stats.php file.
  • Use a web application firewall (WAF) or security plugin to monitor and block attempts to exploit this vulnerability.
  • Regularly scan the website using vulnerability scanning tools to identify and fix vulnerabilities.

Get AI-powered remediation steps tailored to your asset.

Try AI Solutions →

Check your infrastructure.
Right now.

11,000+ scanners. Free to start. No credit card required.

CVE-2021-39350 scanner - Cross-Site Scripting (XSS) vulnerability in FV Flowplayer Video Player plugin for WordPress | S4E