First published: Sat Mar 15 2025(Updated: )
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in NotFound FS Poster. This issue affects FS Poster: from n/a through 6.5.8.
Credit: audit@patchstack.com
Affected Software | Affected Version | How to fix |
---|---|---|
WordPress FS Poster | <=6.5.8 | |
WP RSS Poster | <=6.5.8 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2025-26978 is classified as a high-severity SQL Injection vulnerability in FS Poster.
To fix CVE-2025-26978, update FS Poster to version 6.5.9 or later.
CVE-2025-26978 can allow attackers to execute arbitrary SQL commands on your database, potentially leading to data theft or corruption.
Yes, CVE-2025-26978 can be easily exploited by attackers who can craft specific SQL queries.
CVE-2025-26978 affects all versions of FS Poster from n/a up to and including 6.5.8.