{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/cpes/cpe2.3afs-posterfs-posterwordpress/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":["cpe:2.3:a:fs-poster:fs-poster:*:*:*:*:*:wordpress:*:*"],"_cs_cves":[{"cvss":8.8,"id":"CVE-2026-10195"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["FS-Poster (\u003c= 8.0.1)"],"_cs_severities":["high"],"_cs_tags":["wordpress","rce","web-application","cve"],"_cs_type":"advisory","_cs_vendors":["FS-Poster"],"content_html":"\u003cp\u003eThe FS-Poster plugin for WordPress is affected by a critical vulnerability, tracked as CVE-2026-10195, which enables Remote Code Execution (RCE). The flaw exists due to a combination of insufficient input sanitization of the FFmpeg path configuration parameter and a total lack of authorization checks on specific REST API endpoints. This vulnerability allows an authenticated attacker with a subscriber-level account - a common privilege level for registered users on many WordPress sites - to inject arbitrary commands that are subsequently processed by the server-side exec() function. This issue affects all versions of the plugin up to and including 8.0.1. Because the plugin interfaces directly with system binaries like FFmpeg, successful exploitation grants the attacker the execution context of the web server process (e.g., www-data), potentially leading to site takeover, data exfiltration, or further lateral movement within the hosting environment.\u003c/p\u003e\n\u003ch2 id=\"attack-chain\"\u003eAttack Chain\u003c/h2\u003e\n\u003col\u003e\n\u003cli\u003eAttacker registers an account or uses an existing subscriber-level account on the target WordPress site.\u003c/li\u003e\n\u003cli\u003eAttacker performs discovery to identify active plugins and confirms the presence of FS-Poster via public-facing path disclosures or theme assets.\u003c/li\u003e\n\u003cli\u003eAttacker authenticates to the WordPress site to obtain a valid session cookie and nonces required for API interaction.\u003c/li\u003e\n\u003cli\u003eAttacker crafts a malicious HTTP POST request targeting the vulnerable FS-Poster REST API endpoint.\u003c/li\u003e\n\u003cli\u003eAttacker injects shell metacharacters (e.g., ;, \u0026amp;\u0026amp;, |) into the FFmpeg path parameter within the REST request payload.\u003c/li\u003e\n\u003cli\u003eThe plugin fails to validate or sanitize the FFmpeg path input before passing it to the PHP exec() system call.\u003c/li\u003e\n\u003cli\u003eThe underlying web server process executes the injected commands with the privileges of the web service account.\u003c/li\u003e\n\u003cli\u003eAttacker achieves command execution to download web shells, reverse shells, or exfiltrate configuration files.\u003c/li\u003e\n\u003c/ol\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation of CVE-2026-10195 permits authenticated attackers to execute arbitrary system commands on the WordPress server. This impact is significant for organizations hosting sensitive content, user data, or those using the WordPress instance as an entry point into a larger corporate network. Given that many WordPress sites allow open registration, the barrier to entry is extremely low, potentially exposing thousands of installations to unauthorized server access, site defacement, and total system compromise.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cp\u003ePrioritized actions for security operations and IT teams:\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003eUpdate the FS-Poster plugin to a version beyond 8.0.1 immediately.\u003c/li\u003e\n\u003cli\u003eAudit WordPress user accounts and disable open registration if not required for business operations to mitigate the risk of unauthorized authenticated access.\u003c/li\u003e\n\u003cli\u003eImplement web application firewall (WAF) rules to inspect POST requests to the FS-Poster REST API, specifically monitoring for shell metacharacters in parameters related to binary paths.\u003c/li\u003e\n\u003cli\u003eReview web server access logs for requests to REST API endpoints originating from users with subscriber-level permissions, focusing on unusual POST parameters.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-09-01T17:06:57Z","date_published":"2026-09-01T17:06:57Z","id":"https://feed.craftedsignal.io/briefs/2026-09-cve-2026-10195/","summary":"The FS-Poster WordPress plugin versions up to 8.0.1 contain a remote code execution vulnerability allowing authenticated subscriber-level users to run arbitrary system commands via an unsanitized FFmpeg path parameter.","title":"Remote Code Execution in FS-Poster WordPress Plugin (CVE-2026-10195)","url":"https://feed.craftedsignal.io/briefs/2026-09-cve-2026-10195/"}],"language":"en","title":"CraftedSignal Threat Feed - Cpe:2.3:a:fs-Poster:fs-Poster:*:*:*:*:*:wordpress:*:*","version":"https://jsonfeed.org/version/1.1"}