Cross-site scripting (XSS) vulnerability in view/frontend-head.php in the Flowplayer plugin before 1.2.12 for WordPress allows remote attackers to inject arbitrary web script or HTML via the URI.Referenceshttp://wordpress.org/extend/plugins/fv-wordpress-flowplayer/changelog/http://secunia.com/advisories/46346http://plugins.trac.wordpress.org/changeset?reponame=&new=413607%40fv-wordpress-flowplayer&old=409594%40fv-wordpress-flowplayerhttp://www.securityfocus.com/bid/50008