CVE-2026-83526
Received Received - Intake

Arbitrary File Upload in FV Player WordPress Plugin

Vulnerability report for CVE-2026-83526, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-10-10

Last updated on: 2026-10-10

Assigner: Wordfence

Description

The FV Player 8 plugin for WordPress is vulnerable to Arbitrary File Upload in all versions up to, and including, 8.1.7 via the check_mimetype function. This is due to insufficient file type validation in check_mimetype(), which writes attacker-supplied remote file content to the public uploads directory before any MIME or extension check, combined with a missing capability check on new player creation. This makes it possible for authenticated attackers, with subscriber-level access and above, to upload files that may be executable, which makes remote code execution possible. This requires successfully exploiting a race condition.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-10-10
Last Modified
2026-10-10
Generated
2026-10-10
AI Q&A
2026-10-10
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
foliovision FV Player 8 0

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-434 The product allows the upload or transfer of dangerous file types that are automatically processed within its environment.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

The FV Player 8 WordPress plugin up to version 8.1.7 has an arbitrary file upload vulnerability due to insufficient file type validation in the check_mimetype function. Attackers with subscriber-level access or higher can exploit a race condition to upload executable files to the public uploads directory, enabling remote code execution.

Detection Guidance

Check if the FV Player 8 plugin version is 8.1.7 or lower. Inspect WordPress uploads directory for unexpected executable files. Review server logs for unauthorized file uploads or remote file access attempts.

Impact Analysis

Authenticated attackers with subscriber-level access or higher could upload malicious files to your WordPress site, potentially leading to remote code execution. This could allow attackers to take control of your website, steal data, or use it for further attacks.

Compliance Impact

This vulnerability could lead to unauthorized access and data breaches, violating GDPR and HIPAA compliance requirements for data protection and security. Organizations may face legal penalties and reputational damage if exploited.

Mitigation Strategies

Update FV Player plugin to version 8.1.8 or later immediately. Remove or restrict subscriber-level access if not required. Monitor uploads directory for suspicious files and implement stricter file upload validation.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-83526. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart