{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/products/frontend-post-submission-manager-lite--frontend-posting-wordpress-plugin--1.3.4/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":["cpe:2.3:a:frontend_post_submission_manager_lite_project:frontend_post_submission_manager_lite:*:*:*:*:*:wordpress:*:*"],"_cs_cves":[{"cvss":7.2,"id":"CVE-2026-96649"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["Frontend Post Submission Manager Lite – Frontend Posting WordPress Plugin (\u003c= 1.3.4)"],"_cs_severities":["high"],"_cs_tags":["xss","web-application","wordpress"],"_cs_type":"advisory","_cs_vendors":[],"content_html":"\u003cp\u003eThe Frontend Post Submission Manager Lite - Frontend Posting WordPress Plugin is vulnerable to stored DOM-based Cross-Site Scripting (XSS) due to insufficient input sanitization and output escaping. Specifically, the 'post_content' parameter utilizes a vulnerable 'data-label' DOM sink. This vulnerability affects all versions up to and including 1.3.4.\u003c/p\u003e\n\u003cp\u003eThe flaw is exploitable by unauthenticated attackers, provided the site operator has enabled guest post submissions using the [fpsm] shortcode. The plugin registers a public AJAX handler that relies on a nonce; however, because the nonce is emitted on every page containing the shortcode, it is effectively trivial for an attacker to obtain. Successful exploitation allows for the execution of arbitrary web scripts in the browser of any user who views the compromised post, potentially leading to session hijacking, defacement, or administrative account takeover if an administrator views the content.\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation allows unauthenticated attackers to execute arbitrary JavaScript in the context of other users visiting the affected site. This can lead to complete compromise of user sessions, unauthorized actions performed on behalf of legitimate users, and potential administrative account takeover, depending on the privileges of the victim viewing the injected content.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cp\u003eUpdate the \u0026quot;Frontend Post Submission Manager Lite - Frontend Posting WordPress Plugin\u0026quot; to the latest available version beyond 1.3.4 to resolve the input sanitization flaw. If an update is not immediately available, disable the guest post submission feature by removing the [fpsm] shortcode from all public-facing pages to mitigate the risk of unauthenticated exploitation.\u003c/p\u003e\n","date_modified":"2026-09-30T04:31:42Z","date_published":"2026-09-30T04:31:42Z","id":"https://feed.craftedsignal.io/briefs/2026-09-cve-2026-96649/","summary":"An unauthenticated stored DOM-based XSS vulnerability in the Frontend Post Submission Manager Lite plugin (\u003c= 1.3.4) allows script injection via the post_content parameter when guest submissions are enabled.","title":"Stored DOM-Based XSS in Frontend Post Submission Manager Lite","url":"https://feed.craftedsignal.io/briefs/2026-09-cve-2026-96649/"}],"language":"en","title":"CraftedSignal Threat Feed - Frontend Post Submission Manager Lite – Frontend Posting WordPress Plugin (\u003c= 1.3.4)","version":"https://jsonfeed.org/version/1.1"}