The FS-Poster plugin for WordPress is vulnerable to Remote Code Execution in versions up to and including 8.0.1. This is due to insufficient input sanitization of the FFmpeg path parameter before passing it to the exec() function, combined with missing authorization checks on the REST API endpoints. This makes it possible for authenticated attackers, with subscriber-level access and above, to execute arbitrary commands on the underlying server.
Metrics
Affected Vendors & Products
References
History
Wed, 02 Sep 2026 22:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Fs-code
Fs-code fs Poster - Wordpress Social Media Auto Poster & Scheduler [facebook, Instagram, Twitter, Pinterest] Wordpress Wordpress wordpress |
|
| Vendors & Products |
Fs-code
Fs-code fs Poster - Wordpress Social Media Auto Poster & Scheduler [facebook, Instagram, Twitter, Pinterest] Wordpress Wordpress wordpress |
Tue, 01 Sep 2026 22:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | The FS-Poster plugin for WordPress is vulnerable to Remote Code Execution in versions up to and including 8.0.1. This is due to insufficient input sanitization of the FFmpeg path parameter before passing it to the exec() function, combined with missing authorization checks on the REST API endpoints. This makes it possible for authenticated attackers, with subscriber-level access and above, to execute arbitrary commands on the underlying server. | |
| Title | FS Poster <= 8.0.1 - Authenticated (Subscriber+) Remote Code Execution via FFmpeg Path Setting | |
| Weaknesses | CWE-77 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: Wordfence
Published: 2026-09-01T15:30:56.119Z
Updated: 2026-09-01T17:07:08.276Z
Reserved: 2026-05-31T02:34:59.878Z
Link: CVE-2026-10195
Updated: 2026-09-01T17:07:02.562Z
Status : Deferred
Published: 2026-09-01T16:16:47.467
Modified: 2026-09-01T20:47:54.130
Link: CVE-2026-10195
No data.