Sceawere

Vulnerability Detail

CVE-2026-96649UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

Stored DOM-XSS in Frontend Post Submission Manager Lite

Vulnerability Metadata

Severity
High
Score / CVSS
7.2
Creation Date
4h ago
Vendor
wpshuffle
Product
Frontend Post Submission Manager Lite – Guest Post and Frontend Submission Forms
Attack Type
CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
Vector String
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:N
Attack Complexity
LOW

Narrative and Response

Description

The Frontend Post Submission Manager Lite – Frontend Posting WordPress Plugin plugin for WordPress is vulnerable to Stored DOM-Based Cross-Site Scripting via post_content Parameter (data-label DOM Sink) in all versions up to, and including, 1.3.4 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. This requires the site operator to have enabled guest post submission via the [fpsm] shortcode, which registers a publicly accessible AJAX handler gated only by a nonce emitted on every page containing the shortcode.

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "7.2",
  "pubDate": "2026-09-30T03:17:00.387Z",
  "pubdate": "2026-09-30T03:17:00.387Z",
  "executiveSummary": "The Frontend Post Submission Manager Lite WordPress plugin is susceptible to Stored DOM-Based Cross-Site Scripting (XSS).\nThe vulnerability originates from inadequate input sanitization and output escaping within the post_content parameter, specifically targeting the data-label DOM sink.\nUnauthenticated attackers can exploit this flaw if the site operator has enabled guest post submissions via the [fpsm] shortcode.\nSuccessful exploitation allows for the injection of arbitrary malicious scripts into pages containing the shortcode, which execute whenever a user views the compromised page.\nThis vulnerability poses a significant risk to site integrity and user session security, potentially leading to unauthorized actions, session hijacking, or credential theft.\nThe attack vector relies on the plugin's AJAX handler, which relies on a nonce that is exposed on pages containing the [fpsm] shortcode, significantly lowering the barrier for unauthenticated adversaries.",
  "technicalDetails": "The vulnerability resides in the Frontend Post Submission Manager Lite plugin, affecting all versions up to and including 1.3.4. The flaw is categorized as Stored DOM-Based Cross-Site Scripting, triggered by improper handling of user-supplied data within the post_content parameter.\nThe root cause is the failure of the application to properly sanitize incoming data and escape outgoing content before it reaches the data-label DOM sink. Because the plugin processes guest submissions directly via a publicly accessible AJAX handler, it fails to enforce sufficient security controls on the input stream.\nThe exploitation process follows a specific sequence. First, the attacker identifies a page on the WordPress site that hosts the [fpsm] shortcode. The presence of this shortcode causes the application to emit a nonce, which is necessary for the AJAX handler's interaction. By inspecting the page source or network traffic, the unauthenticated attacker obtains this nonce.\nSecond, the attacker constructs a malicious payload containing JavaScript, which is then submitted through the post_content parameter via the AJAX handler. Since the plugin performs insufficient server-side sanitization, the malicious script is stored directly in the WordPress database.\nThird, once the post containing the malicious script is stored, it becomes active on any page rendering that post content. When a user—who could be a visitor or an administrator—navigates to a page displaying the malicious post, the browser interprets the script as legitimate code.\nThe DOM sink, specifically the data-label parameter, acts as the point of execution. When the client-side JavaScript processes this data, it forces the execution of the attacker's payload within the context of the user's session. This allows the attacker to execute arbitrary actions on behalf of the victim, bypass CSRF protections, or exfiltrate sensitive data such as session cookies or authentication tokens.\nThis vulnerability is particularly critical due to its unauthenticated nature and the relative ease of obtaining the required nonce. By exploiting this flaw, an attacker gains the ability to compromise any user accessing the affected page, regardless of the user's privilege level, effectively turning client-side execution into a persistent, cross-site threat."
}
CVE-2026-96649: Stored DOM-XSS in Frontend Post Submission Manager Lite (HIGH Severity, CVSS: 7.2) | Sceawere