Impact
The vulnerability is a classic SQL injection flaw (CWE‑89) in the FS Poster WordPress plugin, allowing an attacker to craft input that is directly incorporated into SQL commands. By exploiting this flaw, an adversary can read, modify, or delete data stored in the WordPress database, potentially exposing sensitive user information or tampering with site content.
Affected Systems
The issue affects the "FS Poster" plugin provided by fs‑code, impacting all installations from any version up through 6.5.8. The vendor list includes only this single plugin.
Risk and Exploitability
The CVSS score of 8.5 rates the vulnerability as high, and the EPSS score of less than 1% suggests a low likelihood of current exploitation. The vulnerability is not listed in CISA’s KEV catalog. The most likely attack vector is through web requests that target the plugin’s database query endpoints; the description implies that the flaw is triggered by user-supplied data within HTTP requests.
OpenCVE Enrichment
EUVD