Product
The FV Player 8 WordPress plugin is vulnerable to arbitrary file upload via the check_mimetype function, allowing authenticated subscribers to execute remote code via race condition exploitation.