Skip to content
Threat Feed
high advisory

Stored DOM-Based XSS in Frontend Post Submission Manager Lite

An unauthenticated stored DOM-based XSS vulnerability in the Frontend Post Submission Manager Lite plugin (<= 1.3.4) allows script injection via the post_content parameter when guest submissions are enabled.

CVE search metadata

CVE search record: CVE-2026-96649. Severity: high. CVSS: 7.2. KEV: no. Product: Frontend Post Submission Manager Lite – Frontend Posting WordPress Plugin (<= 1.3.4). Brief: Stored DOM-Based XSS in Frontend Post Submission Manager Lite. Brief link: https://feed.craftedsignal.io/briefs/2026-09-cve-2026-96649/

The Frontend Post Submission Manager Lite - Frontend Posting WordPress Plugin is vulnerable to stored DOM-based Cross-Site Scripting (XSS) due to insufficient input sanitization and output escaping. Specifically, the 'post_content' parameter utilizes a vulnerable 'data-label' DOM sink. This vulnerability affects all versions up to and including 1.3.4.

The flaw is exploitable by unauthenticated attackers, provided the site operator has enabled guest post submissions using the [fpsm] shortcode. The plugin registers a public AJAX handler that relies on a nonce; however, because the nonce is emitted on every page containing the shortcode, it is effectively trivial for an attacker to obtain. Successful exploitation allows for the execution of arbitrary web scripts in the browser of any user who views the compromised post, potentially leading to session hijacking, defacement, or administrative account takeover if an administrator views the content.

Impact

Successful exploitation allows unauthenticated attackers to execute arbitrary JavaScript in the context of other users visiting the affected site. This can lead to complete compromise of user sessions, unauthorized actions performed on behalf of legitimate users, and potential administrative account takeover, depending on the privileges of the victim viewing the injected content.

Recommendation

Update the "Frontend Post Submission Manager Lite - Frontend Posting WordPress Plugin" to the latest available version beyond 1.3.4 to resolve the input sanitization flaw. If an update is not immediately available, disable the guest post submission feature by removing the [fpsm] shortcode from all public-facing pages to mitigate the risk of unauthenticated exploitation.


Immediate actions

Audit site for the use of [fpsm] shortcode and disable guest submissions if not explicitly required

IT Operations 24h

Mitigations

Upgrade Frontend Post Submission Manager Lite to a version beyond 1.3.4

immediate IT Operations

CVE-2026-96649