Stored DOM-Based XSS in Frontend Post Submission Manager Lite
An unauthenticated stored DOM-based XSS vulnerability in the Frontend Post Submission Manager Lite plugin (<= 1.3.4) allows script injection via the post_content parameter when guest submissions are enabled.
CVE search metadata
CVE search record: CVE-2026-96649. Severity: high. CVSS: 7.2. KEV: no. Product: Frontend Post Submission Manager Lite – Frontend Posting WordPress Plugin (<= 1.3.4). Brief: Stored DOM-Based XSS in Frontend Post Submission Manager Lite. Brief link: https://feed.craftedsignal.io/briefs/2026-09-cve-2026-96649/
The Frontend Post Submission Manager Lite - Frontend Posting WordPress Plugin is vulnerable to stored DOM-based Cross-Site Scripting (XSS) due to insufficient input sanitization and output escaping. Specifically, the 'post_content' parameter utilizes a vulnerable 'data-label' DOM sink. This vulnerability affects all versions up to and including 1.3.4.
The flaw is exploitable by unauthenticated attackers, provided the site operator has enabled guest post submissions using the [fpsm] shortcode. The plugin registers a public AJAX handler that relies on a nonce; however, because the nonce is emitted on every page containing the shortcode, it is effectively trivial for an attacker to obtain. Successful exploitation allows for the execution of arbitrary web scripts in the browser of any user who views the compromised post, potentially leading to session hijacking, defacement, or administrative account takeover if an administrator views the content.
Impact
Successful exploitation allows unauthenticated attackers to execute arbitrary JavaScript in the context of other users visiting the affected site. This can lead to complete compromise of user sessions, unauthorized actions performed on behalf of legitimate users, and potential administrative account takeover, depending on the privileges of the victim viewing the injected content.
Recommendation
Update the "Frontend Post Submission Manager Lite - Frontend Posting WordPress Plugin" to the latest available version beyond 1.3.4 to resolve the input sanitization flaw. If an update is not immediately available, disable the guest post submission feature by removing the [fpsm] shortcode from all public-facing pages to mitigate the risk of unauthenticated exploitation.
Immediate actions
Audit site for the use of [fpsm] shortcode and disable guest submissions if not explicitly required
Mitigations
Upgrade Frontend Post Submission Manager Lite to a version beyond 1.3.4
CVE-2026-96649