<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:webfeeds="http://webfeeds.org/rss/1.0"><channel><title>Cpe:2.3:a:foliovision:fv_player:*:*:*:*:*:wordpress:*:* - CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/cpes/cpe2.3afoliovisionfv_playerwordpress/</link><description>Trending threats, MITRE ATT&amp;CK coverage, and detection metadata. Fed continuously.</description><generator>Hugo</generator><language>en</language><managingEditor>hello@craftedsignal.io</managingEditor><webMaster>hello@craftedsignal.io</webMaster><lastBuildDate>Sat, 10 Oct 2026 07:51:28 +0000</lastBuildDate><atom:link href="https://feed.craftedsignal.io/cpes/cpe2.3afoliovisionfv_playerwordpress/feed.xml" rel="self" type="application/rss+xml"/><image><url>https://feed.craftedsignal.io/favicon-32x32.png</url><title>CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/</link><width>32</width><height>32</height></image><webfeeds:icon>https://feed.craftedsignal.io/favicon.svg</webfeeds:icon><item><title>Arbitrary File Upload Vulnerability in FV Player 8 Plugin</title><link>https://feed.craftedsignal.io/briefs/2026-10-fv-player-upload/</link><pubDate>Sat, 10 Oct 2026 07:51:28 +0000</pubDate><author>hello@craftedsignal.io</author><guid isPermaLink="true">https://feed.craftedsignal.io/briefs/2026-10-fv-player-upload/</guid><description>The FV Player 8 WordPress plugin is vulnerable to arbitrary file upload via the check_mimetype function, allowing authenticated subscribers to execute remote code via race condition exploitation.</description><content:encoded><![CDATA[<p>The FV Player 8 plugin for WordPress is vulnerable to an arbitrary file upload flaw affecting all versions up to and including 8.1.7. The vulnerability exists within the check_mimetype() function, which fails to adequately validate file types before writing user-supplied remote content to the public web-accessible uploads directory. Furthermore, the creation of new players lacks necessary capability checks, enabling authenticated attackers with subscriber-level permissions to trigger the upload process. By leveraging a race condition during the validation phase, an attacker can bypass security checks to upload executable files, ultimately achieving remote code execution (RCE) on the underlying server.</p>
<h2 id="impact">Impact</h2>
<p>Successful exploitation of this vulnerability allows authenticated users with minimal privileges (subscribers) to upload and execute arbitrary code on the web server. This can lead to full site compromise, unauthorized access to sensitive database information, and the potential for further lateral movement within the hosting environment.</p>
<h2 id="recommendation">Recommendation</h2>
<ul>
<li>Upgrade the FV Player 8 plugin to a version released after 8.1.7 immediately to mitigate this vulnerability.</li>
<li>Review access control logs for users with 'subscriber' roles that have recently accessed the FV Player 8 plugin's player creation or file upload endpoints.</li>
<li>Inspect the WordPress 'wp-content/uploads' directory for suspicious files, particularly those with executable extensions that do not align with expected media assets.</li>
</ul>
]]></content:encoded><category domain="severity">high</category><category domain="type">advisory</category></item></channel></rss>