Description
The Frontend Post Submission Manager Lite – Frontend Posting WordPress Plugin plugin for WordPress is vulnerable to Stored DOM-Based Cross-Site Scripting via post_content Parameter (data-label DOM Sink) in all versions up to, and including, 1.3.4 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. This requires the site operator to have enabled guest post submission via the [fpsm] shortcode, which registers a publicly accessible AJAX handler gated only by a nonce emitted on every page containing the shortcode.
Published: 2026-09-30
Score: 7.2 High
EPSS: < 1% Very Low
KEV: No
Impact: Client‑side Cross‑Site Scripting via unauthenticated post content submission
Action: Immediate Patch
AI Analysis

Impact

The Frontend Post Submission Manager Lite plugin stores user supplied content without adequate sanitization or escaping, allowing an attacker to embed malicious JavaScript into the post_content field. When a site owner has enabled guest post submission using the [fpsm] shortcode, this injected code is rendered and executed in the browsers of any visitor who loads the affected page. Because the injection occurs in the page’s DOM, it bypasses usual server‑side output filtering and can seize the victim’s session, steal cookies, or perform further phishing actions. Affected systems include the WordPress plugin wpshuffle: Frontend Post Submission Manager Lite version 1.3.4 and all earlier releases that still contain the unpatched JavaScript handlers. The 1.3.5 release shows no evidence of the vulnerable code paths, so sites running that or newer versions are no longer susceptible.

Affected Systems

The vulnerability affects the WordPress plugin wpshuffle: Frontend Post Submission Manager Lite versions up to and including 1.3.4. All prior releases contain the same vulnerable JavaScript handlers. Upgrading to 1.3.5 or later removes the security flaw. Sites running 1.3.5 or newer are considered safe.

Risk and Exploitability

The vulnerability is rated CVSS 7.2, indicating a moderate‑to‑high severity risk. Exploitation does not require authentication; an attacker only needs the guest post form facilitated by the [fpsm] shortcode to submit malicious content. No EPSS data is available and the issue is not listed in the CISA KEV catalog, yet the presence of unauthenticated DOM XSS poses a real threat to unsuspecting site visitors and can lead to session hijacking, cookie theft, or phishing activities.

Generated by OpenCVE AI on September 30, 2026 at 07:50 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade Frontend Post Submission Manager Lite to version 1.3.5 or later, which removes the vulnerable DOM sink.
  • If an upgrade cannot be performed immediately, disable guest post submission or remove the [fpsm] shortcode so that unauthenticated submissions are no longer accepted.
  • Audit existing posts for injected JavaScript and cleanse or delete any malicious content before it is displayed to users.

Generated by OpenCVE AI on September 30, 2026 at 07:50 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 30 Sep 2026 02:45:00 +0000

Type Values Removed Values Added
Description The Frontend Post Submission Manager Lite – Frontend Posting WordPress Plugin plugin for WordPress is vulnerable to Stored DOM-Based Cross-Site Scripting via post_content Parameter (data-label DOM Sink) in all versions up to, and including, 1.3.4 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. This requires the site operator to have enabled guest post submission via the [fpsm] shortcode, which registers a publicly accessible AJAX handler gated only by a nonce emitted on every page containing the shortcode.
Title Frontend Post Submission Manager Lite <= 1.3.4 - Unauthenticated Stored DOM-Based Cross-Site Scripting via post_content Parameter (data-label DOM Sink)
Weaknesses CWE-79
References
Metrics cvssV3_1

{'score': 7.2, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:N'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: Wordfence

Published:

Updated: 2026-09-30T15:28:11.965Z

Reserved: 2026-09-23T14:41:49.218Z

Link: CVE-2026-96649

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Deferred

Published: 2026-09-30T03:17:00.387

Modified: 2026-09-30T14:04:38.183

Link: CVE-2026-96649

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-30T08:00:07Z

Weaknesses
  • CWE-79

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')