Stored DOM-Based Cross-Site Scripting in Frontend Post Submission Manager Lite for WordPress
CVE-2026-96649

7.2HIGH

What is CVE-2026-96649?

The Frontend Post Submission Manager Lite plugin for WordPress has a vulnerability that allows unauthenticated attackers to exploit the post_content parameter through insufficient input sanitization and inadequate output escaping. If the site allows guest post submissions via the [fpsm] shortcode, attackers can inject malicious JavaScript code into posts. This script will run every time a user accesses the modified page, posing significant security risks to users and their data. It is crucial for site operators to disable guest post submissions or update to the latest version to mitigate this vulnerability.

Affected Version(s)

Frontend Post Submission Manager Lite – Guest Post and Frontend Submission Forms 0 <= 1.3.4

References

CVSS V3.1

Score:
7.2
Severity:
HIGH
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Tarcísio Luchesi De Almeida Silva (Poystick)
.