Product
The FS-Poster WordPress plugin versions up to 8.0.1 contain a remote code execution vulnerability allowing authenticated subscriber-level users to run arbitrary system commands via an unsanitized FFmpeg path parameter.