CVE-2019-13573: Foliovision Fv Flowplayer Video Player

Critical severity, CVSS 9.8. EPSS: 4.4% chance of exploitation in the next 30 days.

A SQL injection vulnerability exists in the FolioVision FV Flowplayer Video Player plugin before 7.3.19.727 for WordPress. Successful exploitation of this vulnerability would allow a remote attacker to execute arbitrary SQL commands on the affected system.

Affected products

  • Foliovision Fv Flowplayer Video Player: before 7.3.19.727 (fixed in 7.3.19.727)

Published 2019-07-17. Last modified 2026-06-17.