CVE-2026-10195
FS Poster <= 8.0.1 - Authenticated (Subscriber+) Remote Code Execution via FFmpeg Path Setting
CVSS Score
8.8
EPSS Score
0.0%
EPSS Percentile
0th
The FS-Poster plugin for WordPress is vulnerable to Remote Code Execution in versions up to and including 8.0.1. This is due to insufficient input sanitization of the FFmpeg path parameter before passing it to the exec() function, combined with missing authorization checks on the REST API endpoints. This makes it possible for authenticated attackers, with subscriber-level access and above, to execute arbitrary commands on the underlying server.
| CWE | CWE-77 |
| Vendor | fs-code |
| Product | fs poster - wordpress social media auto poster & scheduler [facebook, instagram, twitter, pinterest] |
| Published | Sep 1, 2026 |
| Last Updated | Sep 1, 2026 |
Stay Ahead of the Next One
Get instant alerts for fs-code fs poster - wordpress social media auto poster & scheduler [facebook, instagram, twitter, pinterest]
Be the first to know when new high vulnerabilities affecting fs-code fs poster - wordpress social media auto poster & scheduler [facebook, instagram, twitter, pinterest] are published โ delivered to Slack, Telegram or Discord.
Get Free Alerts โ
Free ยท No credit card ยท 60 sec setup
CVSS v3 Breakdown
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H Attack Vector
Attack Complexity
Privileges Required
User Interaction
Scope
Confidentiality
Integrity
Availability
Affected Versions
fs-code / FS Poster - WordPress Social media Auto Poster & Scheduler [Facebook, Instagram, Twitter, Pinterest]
0 โค 8.0.1
References
Credits
Sullo