Easy Post Submission – Frontend Posting, Guest Publishing & Submit Content for WordPress Security & Risk Analysis

wordpress.org/plugins/easy-post-submission

Enable users to submit posts and manage profiles from the front-end. Ideal for news, magazines, and creative platforms.

2K active installs v2.2.0 PHP 7.4+ WP 6.3+ Updated Dec 26, 2025
anonymous-postfrontend-postguest-postpublic-postuser-post
76
B · Generally Safe
CVEs total2
Unpatched1
Last CVEMar 4, 2026
Safety Verdict

Is Easy Post Submission – Frontend Posting, Guest Publishing & Submit Content for WordPress Safe to Use in 2026?

Mostly Safe

Score 76/100

Easy Post Submission – Frontend Posting, Guest Publishing & Submit Content for WordPress is generally safe to use. 2 past CVEs were resolved. Keep it updated.

2 known CVEs 1 unpatched Last CVE: Mar 4, 2026Updated 3mo ago
Risk Assessment

The "easy-post-submission" plugin version 2.3.0 exhibits a mixed security posture. On the positive side, it demonstrates strong adherence to secure coding practices, with a very high percentage of properly escaped outputs and the use of prepared statements for SQL queries. The absence of dangerous functions, file operations, and critical/high severity taint flows are also encouraging signs. However, a significant concern arises from its attack surface. With 16 AJAX handlers, 4 of which lack authentication checks, there's a clear pathway for unauthorized actions. This is further exacerbated by a history of known vulnerabilities, specifically two medium severity CVEs, with one remaining unpatched. The common vulnerability types mentioned (Missing Authorization, Exposure of Sensitive Information) directly correlate with the identified unprotected AJAX handlers, indicating a recurring pattern of authorization flaws. The presence of an unpatched vulnerability from 2026 is particularly alarming, suggesting a lack of timely security updates.

While the plugin scores well in areas like output escaping and SQL query preparation, the unprotected entry points and the persistent nature of authorization-related vulnerabilities present substantial risks. The unpatched CVE is a critical issue that demands immediate attention. The overall security of "easy-post-submission" v2.3.0 is therefore compromised by these significant, recurring, and unaddressed weaknesses, despite its otherwise good coding hygiene.

Key Concerns

  • Unprotected AJAX handlers
  • Unpatched CVE
  • History of Missing Authorization vulns
Vulnerabilities
2

Easy Post Submission – Frontend Posting, Guest Publishing & Submit Content for WordPress Security Vulnerabilities

CVEs by Year

1 CVE in 2025
2025
1 CVE in 2026 · unpatched
2026
Patched Has unpatched

Severity Breakdown

Medium
2

2 total CVEs

CVE-2026-22479medium · 5.3Missing Authorization

Easy Post Submission – Frontend Posting, Guest Publishing & Submit Content for WordPress <= 2.2.0 - Missing Authorization

Mar 4, 2026Unpatched
CVE-2025-62062medium · 5.3Exposure of Sensitive Information to an Unauthorized Actor

Easy Post Submission <= 1.7.0 - Unauthenticated Sensitive Information Exposure

Oct 16, 2025 Patched in 2.0.0 (8d)
Code Analysis
Analyzed Mar 16, 2026

Easy Post Submission – Frontend Posting, Guest Publishing & Submit Content for WordPress Code Analysis

Dangerous Functions
0
Raw SQL Queries
2
14 prepared
Unescaped Output
2
170 escaped
Nonce Checks
15
Capability Checks
9
File Operations
0
External Requests
4
Bundled Libraries
0

SQL Query Safety

88% prepared16 total queries

Output Escaping

99% escaped172 total outputs
Data Flows
All sanitized

Data Flow Analysis

6 flows
update_post_manager (admin\ajax-handler.php:1164)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface
4 unprotected

Easy Post Submission – Frontend Posting, Guest Publishing & Submit Content for WordPress Attack Surface

Entry Points21
Unprotected4

AJAX Handlers 16

authwp_ajax_rbsm_setupadmin\ajax-handler.php:46
authwp_ajax_rbsm_submit_formadmin\ajax-handler.php:47
authwp_ajax_rbsm_get_formsadmin\ajax-handler.php:48
authwp_ajax_rbsm_update_formadmin\ajax-handler.php:49
authwp_ajax_rbsm_delete_formadmin\ajax-handler.php:50
authwp_ajax_rbsm_get_authorsadmin\ajax-handler.php:51
authwp_ajax_rbsm_admin_get_categoriesadmin\ajax-handler.php:52
authwp_ajax_rbsm_admin_get_tagsadmin\ajax-handler.php:53
authwp_ajax_rbsm_restore_dataadmin\ajax-handler.php:54
authwp_ajax_rbsm_get_post_manageradmin\ajax-handler.php:55
authwp_ajax_rbsm_update_post_manageradmin\ajax-handler.php:56
authwp_ajax_rbsm_submit_postincludes\client-ajax-handler.php:35
noprivwp_ajax_rbsm_submit_postincludes\client-ajax-handler.php:36
authwp_ajax_rbsm_update_postincludes\client-ajax-handler.php:37
authwp_ajax_rbsm_get_user_postsincludes\client-ajax-handler.php:38
authwp_ajax_rbsm_trash_postincludes\client-ajax-handler.php:39

Shortcodes 5

[easy_post_submission_login] includes\account-shortcodes.php:64
[easy_post_submission_register] includes\account-shortcodes.php:65
[easy_post_submission_form] includes\shortcodes.php:63
[easy_post_submission_manager] includes\shortcodes.php:64
[easy_post_submission_edit] includes\shortcodes.php:65
WordPress Hooks 14
filterdisplay_post_statesadmin\admin-menu.php:39
actionadmin_menuadmin\admin-menu.php:40
filterruby_dashboard_menuadmin\admin-menu.php:41
filterplugin_action_linksadmin\admin-menu.php:42
actionadmin_enqueue_scriptsadmin\admin-menu.php:104
actionplugins_loadedeasy-post-submission.php:86
filterquery_varseasy-post-submission.php:87
actionwp_loadedincludes\account-shortcodes.php:68
actionwp_enqueue_scriptsincludes\account-shortcodes.php:71
actionpost_updatedincludes\client-ajax-handler.php:40
actionupgrader_process_completeincludes\recaptcha-migration.php:105
actioninitincludes\shortcodes.php:44
actionwp_enqueue_scriptsincludes\shortcodes.php:61
filterdo_shortcode_tagincludes\shortcodes.php:62
Maintenance & Trust

Easy Post Submission – Frontend Posting, Guest Publishing & Submit Content for WordPress Maintenance & Trust

Maintenance Signals

WordPress version tested6.9.4
Last updatedDec 26, 2025
PHP min version7.4
Downloads14K

Community Trust

Rating100/100
Number of ratings5
Active installs2K
Developer Profile

Easy Post Submission – Frontend Posting, Guest Publishing & Submit Content for WordPress Developer Profile

ThemeRuby

5 plugins · 7K total installs

91
trust score
Avg Security Score
95/100
Avg Patch Time
10 days
View full developer profile
Detection Fingerprints

How We Detect Easy Post Submission – Frontend Posting, Guest Publishing & Submit Content for WordPress

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/easy-post-submission/assets/css/admin/main.css/wp-content/plugins/easy-post-submission/assets/js/admin/main.js/wp-content/plugins/easy-post-submission/assets/css/frontend/main.css/wp-content/plugins/easy-post-submission/assets/js/frontend/main.js
Script Paths
/wp-content/plugins/easy-post-submission/assets/js/admin/main.js/wp-content/plugins/easy-post-submission/assets/js/frontend/main.js
Version Parameters
/wp-content/plugins/easy-post-submission/assets/css/admin/main.css?ver=/wp-content/plugins/easy-post-submission/assets/js/admin/main.js?ver=/wp-content/plugins/easy-post-submission/assets/css/frontend/main.css?ver=/wp-content/plugins/easy-post-submission/assets/js/frontend/main.js?ver=

HTML / DOM Fingerprints

CSS Classes
easy-post-submission-form-wrappereps-submission-formeps-post-titleeps-post-contenteps-post-excerpteps-post-thumbnail-wrapeps-post-category-wrapeps-post-tags-wrap+2 more
HTML Comments
<!-- Easy Post Submission Settings --><!-- Easy Post Submission Form --><!-- Easy Post Submission Shortcode -->
Data Attributes
data-eps-noncedata-eps-post-iddata-eps-user-id
JS Globals
easyPostSubmissionFrontendeasyPostSubmissionAdmin
REST Endpoints
/wp-json/easy-post-submission/v1/submit/wp-json/easy-post-submission/v1/get_form
Shortcode Output
[easy_post_submission_form][easy_post_submission_dashboard][easy_post_submission_edit_profile]
FAQ

Frequently Asked Questions about Easy Post Submission – Frontend Posting, Guest Publishing & Submit Content for WordPress