CVE-2024-32537 PUBLISHED

WordPress Flash Video Player plugin <= 5.0.4 - CSRF to XSS vulnerability

Assigner: Patchstack
Reserved: 15.04.2024 Published: 20.03.2026 Updated: 20.03.2026

Cross-Site request forgery (CSRF) vulnerability in joshuae1974 Flash Video Player allows Cross Site Request Forgery.This issue affects Flash Video Player: from n/a through 5.0.4.

Metrics

CVSS Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L
CVSS Score: 7.1

Product Status

Vendor joshuae1974
Product Flash Video Player
Versions Default: unaffected
  • affected from n/a to 5.0.4 (incl.)

Credits

  • Dimas Maulana | Patchstack Bug Bounty Program finder

References

Problem Types

  • CWE-352 Cross-Site request forgery (CSRF) CWE

Impacts

  • CAPEC-62 Cross Site Request Forgery