CVE-2026-83526 - FV Player 8 <= 8.1.7 - Authenticated (Subscriber+) Arbitrary File Upload via videos[].fv_wp_flowplayer_field_src Parameter
CVE ID :CVE-2026-83526 Published : Oct. 10, 2026, 6:16 a.m. | 1 hour, 13 minutes ago Description :The FV Player 8 plugin for WordPress is vulnerable to Arbitrary File Upload in all versions up to, and including, 8.1.7 via the check_mimetype function. This is due to insufficient file type...