{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/cpes/cpe2.3afoliovisionfv_playerwordpress/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":["cpe:2.3:a:foliovision:fv_player:*:*:*:*:*:wordpress:*:*"],"_cs_cves":[{"cvss":8.8,"id":"CVE-2026-83526"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["FV Player 8 (\u003c= 8.1.7)"],"_cs_severities":["high"],"_cs_tags":[],"_cs_type":"advisory","_cs_vendors":["Folio Vision"],"content_html":"\u003cp\u003eThe FV Player 8 plugin for WordPress is vulnerable to an arbitrary file upload flaw affecting all versions up to and including 8.1.7. The vulnerability exists within the check_mimetype() function, which fails to adequately validate file types before writing user-supplied remote content to the public web-accessible uploads directory. Furthermore, the creation of new players lacks necessary capability checks, enabling authenticated attackers with subscriber-level permissions to trigger the upload process. By leveraging a race condition during the validation phase, an attacker can bypass security checks to upload executable files, ultimately achieving remote code execution (RCE) on the underlying server.\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation of this vulnerability allows authenticated users with minimal privileges (subscribers) to upload and execute arbitrary code on the web server. This can lead to full site compromise, unauthorized access to sensitive database information, and the potential for further lateral movement within the hosting environment.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eUpgrade the FV Player 8 plugin to a version released after 8.1.7 immediately to mitigate this vulnerability.\u003c/li\u003e\n\u003cli\u003eReview access control logs for users with 'subscriber' roles that have recently accessed the FV Player 8 plugin's player creation or file upload endpoints.\u003c/li\u003e\n\u003cli\u003eInspect the WordPress 'wp-content/uploads' directory for suspicious files, particularly those with executable extensions that do not align with expected media assets.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-10-10T07:51:28Z","date_published":"2026-10-10T07:51:28Z","id":"https://feed.craftedsignal.io/briefs/2026-10-fv-player-upload/","summary":"The FV Player 8 WordPress plugin is vulnerable to arbitrary file upload via the check_mimetype function, allowing authenticated subscribers to execute remote code via race condition exploitation.","title":"Arbitrary File Upload Vulnerability in FV Player 8 Plugin","url":"https://feed.craftedsignal.io/briefs/2026-10-fv-player-upload/"}],"language":"en","title":"CraftedSignal Threat Feed - Cpe:2.3:a:foliovision:fv_player:*:*:*:*:*:wordpress:*:*","version":"https://jsonfeed.org/version/1.1"}