PT-2026-103007 · WordPress · Frontend Post Submission Manager Lite

CVE-2026-96649

·

Published

2026-09-30

·

Updated

2026-09-30

CVSS v3.1

7.2

High

VectorAV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions Frontend Post Submission Manager Lite – Frontend Posting WordPress Plugin versions prior to 1.3.5
Description Insufficient input sanitization and output escaping allow unauthenticated attackers to perform Stored DOM-Based Cross-Site Scripting. This occurs via the post content parameter, which acts as a data-label DOM Sink. Attackers can inject arbitrary web scripts into pages that execute when accessed by users. This issue is exploitable if the site operator has enabled guest post submission using the [fpsm] shortcode, which registers a publicly accessible AJAX handler protected only by a nonce.
Recommendations Update the plugin to a version newer than 1.3.4. As a temporary mitigation, disable guest post submission by removing the [fpsm] shortcode from the site.

Fix

XSS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-96649

Affected Products

Frontend Post Submission Manager Lite