plugin

Frontend Post Submission Manager Lite Vulnerabilities

7 known security issues reported for the Frontend Post Submission Manager Lite WordPress plugin. Most recent disclosed Feb 17, 2026.

4 medium

Running Frontend Post Submission Manager Lite on your site? Check whether your installed version is affected.

Scan your site free

Frontend Post Submission Manager Lite <= 1.2.7 - Unauthenticated Open Redirect via 'requested_page' Parameter

medium

The Frontend Post Submission Manager Lite plugin for WordPress is vulnerable to Open Redirection in all versions up to, and including, 1.2.7 due to insufficient validation on the 'requested_page' POST parameter in the verify_username_password function. This makes it possible for unauthenticated attackers to redirect us...

CVSS:
6.1
Affected:
1.0.0 – 1.2.7
Fixed in:
1.2.8
Disclosed:
Feb 17, 2026

CVE-2026-1296 on NVD →

Frontend Post Submission Manager Lite <= 1.2.6 - Incorrect Authorization to Unauthenticated Arbitrary Attachment Deletion

medium

The Frontend Post Submission Manager Lite – Frontend Posting WordPress Plugin plugin for WordPress is vulnerable to unauthorized loss of data due to an incorrect authorization check on the 'media_delete_action' function in all versions up to, and including, 1.2.6. This makes it possible for unauthenticated attackers to...

CVSS:
5.3
Affected:
up to 1.2.6
Fixed in:
1.2.7
Disclosed:
Dec 25, 2025

CVE-2025-14913 on NVD →

Frontend Post Submission Manager Lite &#8211; Frontend Posting WordPress Plugin [frontend-post-submission-manager-lite] < 1.2.7

unknown

[en] The Frontend Post Submission Manager Lite – Frontend Posting WordPress Plugin plugin for WordPress is vulnerable to unauthorized loss of data due to an incorrect authorization check on the 'media_delete_action' function in all versions up to, and including, 1.2.6. This makes it possible for unauthenticated attacke...

Affected:
up to 1.2.7
Fixed in:
1.2.7
Disclosed:
Dec 25, 2025

CVE-2025-14913 on NVD →

Frontend Post Submission Manager Lite &#8211; Frontend Posting WordPress Plugin [frontend-post-submission-manager-lite] < 1.2.6

unknown

[en] The Frontend Post Submission Manager Lite plugin for WordPress is vulnerable to Missing Authorization in all versions up to, and including, 1.2.5. This is due to missing authorization checks on the post update functionality in the fpsml_form_process AJAX action. This makes it possible for unauthenticated attackers...

Affected:
up to 1.2.6
Fixed in:
1.2.6
Disclosed:
Dec 21, 2025

CVE-2025-14080 on NVD →

Frontend Post Submission Manager Lite <= 1.2.5 - Missing Authorization to Unauthenticated Arbitrary Post Modification

medium

The Frontend Post Submission Manager Lite plugin for WordPress is vulnerable to Missing Authorization in all versions up to, and including, 1.2.5. This is due to missing authorization checks on the post update functionality in the fpsml_form_process AJAX action. This makes it possible for unauthenticated attackers to m...

CVSS:
5.3
Affected:
up to 1.2.5
Fixed in:
1.2.6
Disclosed:
Dec 20, 2025

CVE-2025-14080 on NVD →

Frontend Post Submission Manager Lite &#8211; Frontend Posting WordPress Plugin [frontend-post-submission-manager-lite] < 1.2.3

unknown

[en] The Frontend Post Submission Manager Lite – Frontend Posting WordPress Plugin plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the save_global_settings and process_form_edit functions in all versions up to, and including, 1.2.2. This makes it possible for...

Affected:
up to 1.2.3
Fixed in:
1.2.3
Disclosed:
Sep 6, 2024

CVE-2024-8427 on NVD →

Frontend Post Submission Manager Lite – Frontend Posting WordPress Plugin <= 1.2.2 - Missing Authorization to Authenticated (Subscriber+) Settings Update

medium

The Frontend Post Submission Manager Lite – Frontend Posting WordPress Plugin plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the save_global_settings and process_form_edit functions in all versions up to, and including, 1.2.2. This makes it possible for auth...

CVSS:
4.3
Affected:
up to 1.2.2
Fixed in:
1.2.3
Disclosed:
Sep 5, 2024

CVE-2024-8427 on NVD →

Protect your WordPress site

Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.

Scan your site free

← Back to the vulnerability database