cleantalk
Vulnerabilities and Security Researches

Vulnerabilities and security researches forfrontend-post-submission-manager-lite frontend-post-submission-manager-lite

Direction: ascending
Sep 07, 2024

Frontend Posting WordPress Plugin – Frontend Post Submission Manager Lite # CVE-2024-8427

CVE, Research URL

CVE-2024-8427

Date
Sep 06, 2024
Research Description
The Frontend Post Submission Manager Lite – Frontend Posting WordPress Plugin plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the save_global_settings and process_form_edit functions in all versions up to, and including, 1.2.2. This makes it possible for authenticated attackers, with Subscriber-level access and above, to update the plugin's settings and forms.
Affected versions
max 1.2.3.
Status
vulnerable
Jan 11, 2026

Frontend Posting WordPress Plugin – Frontend Post Submission Manager Lite # CVE-2025-14913

CVE, Research URL

CVE-2025-14913

Date
Dec 26, 2025
Research Description
The Frontend Post Submission Manager Lite – Frontend Posting WordPress Plugin plugin for WordPress is vulnerable to unauthorized loss of data due to an incorrect authorization check on the 'media_delete_action' function in all versions up to, and including, 1.2.6. This makes it possible for unauthenticated attackers to delete arbitrary attachments.
Affected versions
max 1.2.7.
Status
vulnerable

Frontend Posting WordPress Plugin – Frontend Post Submission Manager Lite # CVE-2025-14080

CVE, Research URL

CVE-2025-14080

Date
Dec 21, 2025
Research Description
The Frontend Post Submission Manager Lite plugin for WordPress is vulnerable to Missing Authorization in all versions up to, and including, 1.2.5. This is due to missing authorization checks on the post update functionality in the fpsml_form_process AJAX action. This makes it possible for unauthenticated attackers to modify arbitrary posts by providing a post_id parameter via the guest posting form, allowing them to change post titles, content, excerpts, and remove post authors.
Affected versions
max 1.2.6.
Status
vulnerable
Apr 14, 2026

Frontend Posting WordPress Plugin – Frontend Post Submission Manager Lite # CVE-2026-1296

CVE, Research URL

CVE-2026-1296

Date
Feb 18, 2026
Research Description
The Frontend Post Submission Manager Lite plugin for WordPress is vulnerable to Open Redirection in all versions up to, and including, 1.2.7 due to insufficient validation on the 'requested_page' POST parameter in the verify_username_password function. This makes it possible for unauthenticated attackers to redirect users to potentially malicious sites if they can successfully trick them into performing an action such as clicking on a link.
Affected versions
max 1.2.8.
Status
vulnerable