๐Ÿ” CVE Alert

CVE-2026-10195

HIGH 8.8

FS Poster <= 8.0.1 - Authenticated (Subscriber+) Remote Code Execution via FFmpeg Path Setting

CVSS Score
8.8
EPSS Score
0.0%
EPSS Percentile
0th

The FS-Poster plugin for WordPress is vulnerable to Remote Code Execution in versions up to and including 8.0.1. This is due to insufficient input sanitization of the FFmpeg path parameter before passing it to the exec() function, combined with missing authorization checks on the REST API endpoints. This makes it possible for authenticated attackers, with subscriber-level access and above, to execute arbitrary commands on the underlying server.

CWE CWE-77
Vendor fs-code
Product fs poster - wordpress social media auto poster & scheduler [facebook, instagram, twitter, pinterest]
Published Sep 1, 2026
Last Updated Sep 1, 2026
Stay Ahead of the Next One

Get instant alerts for fs-code fs poster - wordpress social media auto poster & scheduler [facebook, instagram, twitter, pinterest]

Be the first to know when new high vulnerabilities affecting fs-code fs poster - wordpress social media auto poster & scheduler [facebook, instagram, twitter, pinterest] are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

CVSS v3 Breakdown

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Attack Vector
Attack Complexity
Privileges Required
User Interaction
Scope
Confidentiality
Integrity
Availability

Affected Versions

fs-code / FS Poster - WordPress Social media Auto Poster & Scheduler [Facebook, Instagram, Twitter, Pinterest]
0 โ‰ค 8.0.1

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
wordfence.com: https://www.wordfence.com/threat-intel/vulnerabilities/id/3130d987-6a54-4208-8591-0bb9626858ae?source=cve fs-poster.com: https://www.fs-poster.com/documentation/updates-changelogs

Credits

Sullo