PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-83526 foliovision CVE debrief

The FV Player 8 plugin for WordPress is vulnerable to Arbitrary File Upload in all versions up to, and including, 8.1.7 via the check_mimetype function. This is due to insufficient file type validation in check_mimetype(), which writes attacker-supplied remote file content to the public uploads directory before any MIME or extension check, combined with a missing capability check on new player creation. This makes it possible for authenticated attackers, with subscriber-level access and above, to upload files that may be executable, which makes remote code execution possible. This requires successfully exploiting a race condition.

Vendor
foliovision
Product
FV Player 8
CVSS
HIGH 8.8
CISA KEV
Not listed in stored evidence
Original CVE published
2026-10-10
Original CVE updated
2026-10-10
Advisory published
2026-10-10
Advisory updated
2026-10-10

Who should care

Defenders responsible for WordPress installations with the FV Player 8 plugin should assess exposure and prioritize patching to prevent potential exploitation. This includes reviewing the current version of the plugin, verifying the presence of FV Player 8 version 8.1.7 or earlier, and applying the patch. Additionally, defenders should consider implementing compensating controls for exposed systems while remediation is scheduled and verified.

Why it matters

The FV Player 8 plugin for WordPress is vulnerable to Arbitrary File Upload, allowing authenticated attackers to potentially execute remote code. Defenders should prioritize verifying and patching affected installations.

  • Remote code execution is possible if an attacker successfully exploits the vulnerability
  • Defenders need to verify the presence of FV Player 8 version 8.1.7 or earlier and apply the patch
  • The vulnerability requires authentication with subscriber-level access and above

Technical summary

The FV Player 8 plugin for WordPress is vulnerable to Arbitrary File Upload due to insufficient file type validation in the check_mimetype function and a missing capability check on new player creation. This allows authenticated attackers with subscriber-level access and above to upload potentially executable files, leading to possible remote code execution. The vulnerability requires successfully exploiting a race condition. Defenders should prioritize verifying and patching affected installations to prevent potential exploitation.

Defensive priority

Defenders should prioritize verifying the presence of FV Player 8 version 8.1.7 or earlier and applying the patch to prevent potential arbitrary file uploads.

Recommended defensive actions

  • Verify the version of FV Player 8 and update to a patched version if necessary
  • Restrict file uploads to only allow specific file types
  • Monitor for suspicious file uploads and authentication attempts
  • Implement additional security measures to prevent exploitation of the race condition
  • Review compensating controls for exposed systems while remediation is scheduled and verified
  • Check relevant monitoring, detection, and logs for exposed assets that need extra review
  • Track exceptions, retest remediated assets, and close the item only after evidence is documented

Evidence notes

The CVE record and source item provide details on the vulnerability, including the affected versions and the required authentication level for exploitation. Defenders should verify the presence of FV Player 8 version 8.1.7 or earlier and apply the patch. The vulnerability requires authentication with subscriber-level access and above. There may be additional information available from other sources that defenders should review to assess exposure and prioritize patching.

Sources and references

Verified primary and authoritative sources

  • CVE-2026-83526 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2026-83526

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2026-83526 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2026-83526

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

  • FV Player 8 <= 8.1.7 - Authenticated (Subscriber+) Arbitrary File Upload via videos[].fv_wp_flow

    Unverified legacy reference

    URL: https://raw.githubusercontent.com/CVEProject/cvelistV5/main/cves/2026/83xxx/CVE-2026-83526.json

    cve_program_cvelist_v5

  • Source reference

    Unverified legacy reference

    URL: https://plugins.trac.wordpress.org/browser/fv-player/trunk/models/checker.php

    Supplemental source

  • Source reference

    Unverified legacy reference

    URL: https://plugins.trac.wordpress.org/browser/fv-player/trunk/models/db.php

    Supplemental source

  • Source reference

    Unverified legacy reference

    URL: https://plugins.trac.wordpress.org/browser/fv-player/trunk/models/db-video.php

    Supplemental source

  • Source reference

    Unverified legacy reference

    URL: https://plugins.trac.wordpress.org/browser/fv-player/trunk/controller/editor.php

    Supplemental source

  • Source reference

    Unverified legacy reference

    URL: https://plugins.trac.wordpress.org/browser/fv-player/trunk/controller/frontend.php

    Supplemental source

  • Source reference

    Unverified legacy reference

    URL: https://github.com/foliovision/fv-wordpress-flowplayer/releases/tag/8.1.8

    Supplemental source

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.