Skip to content
Threat Feed
high advisory

Arbitrary File Upload Vulnerability in FV Player 8 Plugin

The FV Player 8 WordPress plugin is vulnerable to arbitrary file upload via the check_mimetype function, allowing authenticated subscribers to execute remote code via race condition exploitation.

CVE search metadata

CVE search record: CVE-2026-83526. Severity: high. CVSS: 8.8. KEV: no. Product: FV Player 8 (<= 8.1.7). Brief: Arbitrary File Upload Vulnerability in FV Player 8 Plugin. Brief link: https://feed.craftedsignal.io/briefs/2026-10-fv-player-upload/

The FV Player 8 plugin for WordPress is vulnerable to an arbitrary file upload flaw affecting all versions up to and including 8.1.7. The vulnerability exists within the check_mimetype() function, which fails to adequately validate file types before writing user-supplied remote content to the public web-accessible uploads directory. Furthermore, the creation of new players lacks necessary capability checks, enabling authenticated attackers with subscriber-level permissions to trigger the upload process. By leveraging a race condition during the validation phase, an attacker can bypass security checks to upload executable files, ultimately achieving remote code execution (RCE) on the underlying server.

Impact

Successful exploitation of this vulnerability allows authenticated users with minimal privileges (subscribers) to upload and execute arbitrary code on the web server. This can lead to full site compromise, unauthorized access to sensitive database information, and the potential for further lateral movement within the hosting environment.

Recommendation

  • Upgrade the FV Player 8 plugin to a version released after 8.1.7 immediately to mitigate this vulnerability.
  • Review access control logs for users with 'subscriber' roles that have recently accessed the FV Player 8 plugin's player creation or file upload endpoints.
  • Inspect the WordPress 'wp-content/uploads' directory for suspicious files, particularly those with executable extensions that do not align with expected media assets.

Immediate actions

Upgrade FV Player 8 to a version post-8.1.7

IT Operations 24h

Mitigations

Upgrade FV Player 8 to a version post-8.1.7

immediate IT Operations

CVE-2026-83526