<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:webfeeds="http://webfeeds.org/rss/1.0"><channel><title>Frontend Post Submission Manager Lite – Frontend Posting WordPress Plugin (&lt;= 1.3.4) - CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/products/frontend-post-submission-manager-lite--frontend-posting-wordpress-plugin--1.3.4/</link><description>Trending threats, MITRE ATT&amp;CK coverage, and detection metadata. Fed continuously.</description><generator>Hugo</generator><language>en</language><managingEditor>hello@craftedsignal.io</managingEditor><webMaster>hello@craftedsignal.io</webMaster><lastBuildDate>Wed, 30 Sep 2026 04:31:42 +0000</lastBuildDate><atom:link href="https://feed.craftedsignal.io/products/frontend-post-submission-manager-lite--frontend-posting-wordpress-plugin--1.3.4/feed.xml" rel="self" type="application/rss+xml"/><image><url>https://feed.craftedsignal.io/favicon-32x32.png</url><title>CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/</link><width>32</width><height>32</height></image><webfeeds:icon>https://feed.craftedsignal.io/favicon.svg</webfeeds:icon><item><title>Stored DOM-Based XSS in Frontend Post Submission Manager Lite</title><link>https://feed.craftedsignal.io/briefs/2026-09-cve-2026-96649/</link><pubDate>Wed, 30 Sep 2026 04:31:42 +0000</pubDate><author>hello@craftedsignal.io</author><guid isPermaLink="true">https://feed.craftedsignal.io/briefs/2026-09-cve-2026-96649/</guid><description>An unauthenticated stored DOM-based XSS vulnerability in the Frontend Post Submission Manager Lite plugin (&lt;= 1.3.4) allows script injection via the post_content parameter when guest submissions are enabled.</description><content:encoded><![CDATA[<p>The Frontend Post Submission Manager Lite - Frontend Posting WordPress Plugin is vulnerable to stored DOM-based Cross-Site Scripting (XSS) due to insufficient input sanitization and output escaping. Specifically, the 'post_content' parameter utilizes a vulnerable 'data-label' DOM sink. This vulnerability affects all versions up to and including 1.3.4.</p>
<p>The flaw is exploitable by unauthenticated attackers, provided the site operator has enabled guest post submissions using the [fpsm] shortcode. The plugin registers a public AJAX handler that relies on a nonce; however, because the nonce is emitted on every page containing the shortcode, it is effectively trivial for an attacker to obtain. Successful exploitation allows for the execution of arbitrary web scripts in the browser of any user who views the compromised post, potentially leading to session hijacking, defacement, or administrative account takeover if an administrator views the content.</p>
<h2 id="impact">Impact</h2>
<p>Successful exploitation allows unauthenticated attackers to execute arbitrary JavaScript in the context of other users visiting the affected site. This can lead to complete compromise of user sessions, unauthorized actions performed on behalf of legitimate users, and potential administrative account takeover, depending on the privileges of the victim viewing the injected content.</p>
<h2 id="recommendation">Recommendation</h2>
<p>Update the &quot;Frontend Post Submission Manager Lite - Frontend Posting WordPress Plugin&quot; to the latest available version beyond 1.3.4 to resolve the input sanitization flaw. If an update is not immediately available, disable the guest post submission feature by removing the [fpsm] shortcode from all public-facing pages to mitigate the risk of unauthenticated exploitation.</p>
]]></content:encoded><category domain="severity">high</category><category domain="type">advisory</category><category>xss</category><category>web-application</category><category>wordpress</category></item></channel></rss>