The FV Flowplayer Video Player WordPress plugin has a security issue that could allow attackers to run malicious code on the website. This affects versions 7.5.0.727 to 7.5.2.727. Attackers can use the player_id parameter in the ~/view/stats.php file to inject web scripts into the website.