PatchSiren cyber security CVE debrief
CVE-2026-83526 foliovision CVE debrief
The FV Player 8 plugin for WordPress is vulnerable to Arbitrary File Upload in all versions up to, and including, 8.1.7 via the check_mimetype function. This is due to insufficient file type validation in check_mimetype(), which writes attacker-supplied remote file content to the public uploads directory before any MIME or extension check, combined with a missing capability check on new player creation. This makes it possible for authenticated attackers, with subscriber-level access and above, to upload files that may be executable, which makes remote code execution possible. This requires successfully exploiting a race condition.
- Vendor
- foliovision
- Product
- FV Player 8
- CVSS
- HIGH 8.8
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-10-10
- Original CVE updated
- 2026-10-10
- Advisory published
- 2026-10-10
- Advisory updated
- 2026-10-10
Who should care
Defenders responsible for WordPress installations with the FV Player 8 plugin should assess exposure and prioritize patching to prevent potential exploitation. This includes reviewing the current version of the plugin, verifying the presence of FV Player 8 version 8.1.7 or earlier, and applying the patch. Additionally, defenders should consider implementing compensating controls for exposed systems while remediation is scheduled and verified.
Why it matters
The FV Player 8 plugin for WordPress is vulnerable to Arbitrary File Upload, allowing authenticated attackers to potentially execute remote code. Defenders should prioritize verifying and patching affected installations.
- Remote code execution is possible if an attacker successfully exploits the vulnerability
- Defenders need to verify the presence of FV Player 8 version 8.1.7 or earlier and apply the patch
- The vulnerability requires authentication with subscriber-level access and above
Technical summary
The FV Player 8 plugin for WordPress is vulnerable to Arbitrary File Upload due to insufficient file type validation in the check_mimetype function and a missing capability check on new player creation. This allows authenticated attackers with subscriber-level access and above to upload potentially executable files, leading to possible remote code execution. The vulnerability requires successfully exploiting a race condition. Defenders should prioritize verifying and patching affected installations to prevent potential exploitation.
Defensive priority
Defenders should prioritize verifying the presence of FV Player 8 version 8.1.7 or earlier and applying the patch to prevent potential arbitrary file uploads.
Recommended defensive actions
- Verify the version of FV Player 8 and update to a patched version if necessary
- Restrict file uploads to only allow specific file types
- Monitor for suspicious file uploads and authentication attempts
- Implement additional security measures to prevent exploitation of the race condition
- Review compensating controls for exposed systems while remediation is scheduled and verified
- Check relevant monitoring, detection, and logs for exposed assets that need extra review
- Track exceptions, retest remediated assets, and close the item only after evidence is documented
Evidence notes
The CVE record and source item provide details on the vulnerability, including the affected versions and the required authentication level for exploitation. Defenders should verify the presence of FV Player 8 version 8.1.7 or earlier and apply the patch. The vulnerability requires authentication with subscriber-level access and above. There may be additional information available from other sources that defenders should review to assess exposure and prioritize patching.
Sources and references
Verified primary and authoritative sources
-
CVE-2026-83526 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2026-83526
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2026-83526 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2026-83526
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
FV Player 8 <= 8.1.7 - Authenticated (Subscriber+) Arbitrary File Upload via videos[].fv_wp_flow
Unverified legacy reference
URL: https://raw.githubusercontent.com/CVEProject/cvelistV5/main/cves/2026/83xxx/CVE-2026-83526.json
cve_program_cvelist_v5
-
Source reference
Unverified legacy reference
URL: https://plugins.trac.wordpress.org/browser/fv-player/trunk/models/checker.php
Supplemental source
-
Source reference
Unverified legacy reference
URL: https://plugins.trac.wordpress.org/browser/fv-player/trunk/models/db.php
Supplemental source
-
Source reference
Unverified legacy reference
URL: https://plugins.trac.wordpress.org/browser/fv-player/trunk/models/db-video.php
Supplemental source
-
Source reference
Unverified legacy reference
URL: https://plugins.trac.wordpress.org/browser/fv-player/trunk/controller/editor.php
Supplemental source
-
Source reference
Unverified legacy reference
URL: https://plugins.trac.wordpress.org/browser/fv-player/trunk/controller/frontend.php
Supplemental source
-
Source reference
Unverified legacy reference
URL: https://github.com/foliovision/fv-wordpress-flowplayer/releases/tag/8.1.8
Supplemental source
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.