PT-2026-103007 · WordPress · Frontend Post Submission Manager Lite
CVE-2026-96649
·
Published
2026-09-30
·
Updated
2026-09-30
CVSS v3.1
7.2
High
| Vector | AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
Frontend Post Submission Manager Lite – Frontend Posting WordPress Plugin versions prior to 1.3.5
Description
Insufficient input sanitization and output escaping allow unauthenticated attackers to perform Stored DOM-Based Cross-Site Scripting. This occurs via the
post content parameter, which acts as a data-label DOM Sink. Attackers can inject arbitrary web scripts into pages that execute when accessed by users. This issue is exploitable if the site operator has enabled guest post submission using the [fpsm] shortcode, which registers a publicly accessible AJAX handler protected only by a nonce.Recommendations
Update the plugin to a version newer than 1.3.4.
As a temporary mitigation, disable guest post submission by removing the
[fpsm] shortcode from the site.Fix
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Frontend Post Submission Manager Lite