CVE-2025-26978: WordPress FS Poster plugin <= 6.5.8 - SQL Injection vulnerability
Published Mar 15, 2025
·Updated
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in fs-code FS Poster fs-poster.This issue affects FS Poster: from n/a through <= 6.5.8.
Affected Software
1 affected component
Fs-code FS Poster<=6.5.8
Event History
Mar 15, 2025
CVE Published
via MITRE·09:57 PM
Data Sourced
via MITRE·09:57 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·10:15 PM
DescriptionWeakness
Frequently Asked Questions
1
What is the severity of CVE-2025-26978?
CVE-2025-26978 is classified as a high-severity SQL Injection vulnerability in FS Poster.
2
How do I fix CVE-2025-26978?
To fix CVE-2025-26978, update FS Poster to version 6.5.9 or later.
3
What impact does CVE-2025-26978 have on my website?
CVE-2025-26978 can allow attackers to execute arbitrary SQL commands on your database, potentially leading to data theft or corruption.
4
Is CVE-2025-26978 easy to exploit?
Yes, CVE-2025-26978 can be easily exploited by attackers who can craft specific SQL queries.
5
What versions of FS Poster are affected by CVE-2025-26978?
CVE-2025-26978 affects all versions of FS Poster from n/a up to and including 6.5.8.