Impact
The Frontend Post Submission Manager Lite plugin stores user supplied content without adequate sanitization or escaping, allowing an attacker to embed malicious JavaScript into the post_content field. When a site owner has enabled guest post submission using the [fpsm] shortcode, this injected code is rendered and executed in the browsers of any visitor who loads the affected page. Because the injection occurs in the page’s DOM, it bypasses usual server‑side output filtering and can seize the victim’s session, steal cookies, or perform further phishing actions. Affected systems include the WordPress plugin wpshuffle: Frontend Post Submission Manager Lite version 1.3.4 and all earlier releases that still contain the unpatched JavaScript handlers. The 1.3.5 release shows no evidence of the vulnerable code paths, so sites running that or newer versions are no longer susceptible.
Affected Systems
The vulnerability affects the WordPress plugin wpshuffle: Frontend Post Submission Manager Lite versions up to and including 1.3.4. All prior releases contain the same vulnerable JavaScript handlers. Upgrading to 1.3.5 or later removes the security flaw. Sites running 1.3.5 or newer are considered safe.
Risk and Exploitability
The vulnerability is rated CVSS 7.2, indicating a moderate‑to‑high severity risk. Exploitation does not require authentication; an attacker only needs the guest post form facilitated by the [fpsm] shortcode to submit malicious content. No EPSS data is available and the issue is not listed in the CISA KEV catalog, yet the presence of unauthenticated DOM XSS poses a real threat to unsuspecting site visitors and can lead to session hijacking, cookie theft, or phishing activities.
OpenCVE Enrichment