{"id":"CVE-2026-83526","summary":"FV Player 8 \u003c= 8.1.7 - Authenticated (Subscriber+) Arbitrary File Upload via videos[].fv_wp_flowplayer_field_src Parameter","details":"The FV Player 8 plugin for WordPress is vulnerable to Arbitrary File Upload in all versions up to, and including, 8.1.7 via the check_mimetype function. This is due to insufficient file type validation in check_mimetype(), which writes attacker-supplied remote file content to the public uploads directory before any MIME or extension check, combined with a missing capability check on new player creation. This makes it possible for authenticated attackers, with subscriber-level access and above, to upload files that may be executable, which makes remote code execution possible. This requires successfully exploiting a race condition.","modified":"2026-10-11T02:47:32.030326903Z","published":"2026-10-10T05:30:58.064Z","database_specific":{"cwe_ids":["CWE-434"],"osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/83xxx/CVE-2026-83526.json","cna_assigner":"Wordfence"},"references":[{"type":"WEB","url":"https://github.com/foliovision/fv-wordpress-flowplayer/releases/tag/8.1.8"},{"type":"WEB","url":"https://plugins.trac.wordpress.org/browser/fv-player/trunk/controller/editor.php#L36"},{"type":"WEB","url":"https://plugins.trac.wordpress.org/browser/fv-player/trunk/controller/frontend.php#L1211"},{"type":"WEB","url":"https://plugins.trac.wordpress.org/browser/fv-player/trunk/models/checker.php#L105"},{"type":"WEB","url":"https://plugins.trac.wordpress.org/browser/fv-player/trunk/models/checker.php#L148"},{"type":"WEB","url":"https://plugins.trac.wordpress.org/browser/fv-player/trunk/models/checker.php#L181"},{"type":"WEB","url":"https://plugins.trac.wordpress.org/browser/fv-player/trunk/models/db-video.php#L855"},{"type":"WEB","url":"https://plugins.trac.wordpress.org/browser/fv-player/trunk/models/db.php#L1102"},{"type":"WEB","url":"https://plugins.trac.wordpress.org/browser/fv-player/trunk/models/db.php#L1173"},{"type":"WEB","url":"https://plugins.trac.wordpress.org/browser/fv-player/trunk/models/db.php#L46"},{"type":"WEB","url":"https://www.wordfence.com/threat-intel/vulnerabilities/id/5c75cb7b-1ebe-411c-8664-848d741e40d4?source=cve"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/83xxx/CVE-2026-83526.json"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-83526"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/foliovision/fv-wordpress-flowplayer","events":[{"introduced":"0"},{"fixed":"cc108f5affede691af0b985444071de199d94637"}],"database_specific":{"extracted_events":[{"introduced":"0"},{"last_affected":"8.1.7"}],"source":["AFFECTED_FIELD","REFERENCES"]}}],"versions":["8.1.7","8.1.6","8.0.26","8.0.13","8.0.10","8.0.8","8.0.7","7.5.12.727","7.4.46.727","7.4.42.727","7.4.40.727","7.4.24.727","7.4.21.727","7.4.9.727","7.4.7.727","7.4.6.727","7.4.2.727","7.4.0.727","7.3.13.727","7.3.12.727","7.3.9.727","7.37.727","7.3.7.727","7.3.6.727","7.3.4.727","7.3.3.727","7.3.1.727","7.3.0.727","7.2.8.727","7.2.7.727","7.2.6.727","7.2.5.727","7.2.4.727","7.2.3.727","7.2.2.727","7.2.1.727","7.2.0.727","7.1.15.727","7.1.14.727","6.6.6"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-83526.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"}]}