Frontend Posting WordPress Plugin – Frontend Post Submission Manager Lite, CVE-2026-1296
- CVE, Research URL
- Home page URL
-
Security reports for Frontend Posting WordPress Plugin – Frontend Post Submission Manager Lite
- Published on
- Feb 18, 2026
- Research Description
- The Frontend Post Submission Manager Lite plugin for WordPress is vulnerable to Open Redirection in all versions up to, and including, 1.2.7 due to insufficient validation on the 'requested_page' POST parameter in the verify_username_password function. This makes it possible for unauthenticated attackers to redirect users to potentially malicious sites if they can successfully trick them into performing an action such as clicking on a link.
- Affected versions
-
max 1.2.8.
- Status
-
vulnerable