WordPress 的 FS-Poster 插件在 8.0.1 及之前版本中存在远程代码执行(RCE)漏洞。该漏洞源于在将 FFmpeg 路径参数传递给 exec() 函数前,输入清理(sanitization)不足,同时 REST API 端点缺少必要的权限验证。这使得拥有订阅者(subscriber)级别或更高权限的已认证攻击者能够在底层服务器上执行任意命令。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| fs-code | FS Poster - WordPress Social media Auto Poster & Scheduler [Facebook, Instagram, Twitter, Pinterest] | 0 ~ 8.0.1 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POCNo comments yet