Stored DOM-Based Cross-Site Scripting in Frontend Post Submission Manager Lite for WordPress
CVE-2026-96649
7.2HIGH
Key Information:
- Vendor
WordPress
- Vendor
- CVE Published:
- 30 September 2026
What is CVE-2026-96649?
The Frontend Post Submission Manager Lite plugin for WordPress has a vulnerability that allows unauthenticated attackers to exploit the post_content parameter through insufficient input sanitization and inadequate output escaping. If the site allows guest post submissions via the [fpsm] shortcode, attackers can inject malicious JavaScript code into posts. This script will run every time a user accesses the modified page, posing significant security risks to users and their data. It is crucial for site operators to disable guest post submissions or update to the latest version to mitigate this vulnerability.
Affected Version(s)
Frontend Post Submission Manager Lite – Guest Post and Frontend Submission Forms 0 <= 1.3.4