Frontend Post Submission Manager Lite – Frontend Posting WordPress Plugin Security & Risk Analysis

wordpress.org/plugins/frontend-post-submission-manager-lite

Frontend Post Submission with or without Login, 5 PreDesigned Form Templates, Add Unlimited Custom Fields, Google Captcha Security, Post Notifications

2K active installs v1.2.8 PHP 7.0+ WP 5.5+ Updated Feb 11, 2026
anonymous-postfrontend-postfrontend-postingguest-postinguser-post
95
A · Safe
CVEs total4
Unpatched0
Last CVEFeb 17, 2026
Safety Verdict

Is Frontend Post Submission Manager Lite – Frontend Posting WordPress Plugin Safe to Use in 2026?

Generally Safe

Score 95/100

Frontend Post Submission Manager Lite – Frontend Posting WordPress Plugin has a strong security track record. Known vulnerabilities have been patched promptly.

4 known CVEsLast CVE: Feb 17, 2026Updated 1mo ago
Risk Assessment

The plugin 'frontend-post-submission-manager-lite' v1.2.8 exhibits a concerning security posture, primarily due to a significant number of unprotected entry points. While the plugin demonstrates good practices in areas like output escaping (93% properly escaped) and SQL prepared statements (67%), the presence of 10 AJAX handlers lacking authentication checks is a major vulnerability. This broad attack surface without proper authorization could allow unauthenticated users to trigger potentially sensitive actions.

The taint analysis further amplifies these concerns, revealing 8 high-severity flows with unsanitized paths. This suggests that user-supplied data might be improperly handled, leading to potential code execution or unauthorized access. While no critical taint flows were identified, the high number of high-severity ones remains a significant risk. The plugin's vulnerability history, with 4 medium-severity CVEs in the past, predominantly related to 'Open Redirect' and 'Missing Authorization', reinforces the pattern of authorization weaknesses.

Despite the robust output escaping and SQL practices, the sheer volume of unprotected AJAX endpoints and the critical taint analysis findings present a substantial risk. The past vulnerabilities indicate a recurring issue with authorization, which appears to be a fundamental weakness in this plugin. Users should exercise extreme caution and consider delaying updates or seeking alternative solutions until these authorization and taint flow issues are addressed.

Key Concerns

  • 10 unprotected AJAX handlers
  • 8 high severity taint flows
  • 4 medium severity CVEs historically
  • 6 SQL queries without prepared statements
  • 2 file operations
  • 2 external HTTP requests
  • 3 capability checks vs 10 unprotected AJAX handlers
Vulnerabilities
4

Frontend Post Submission Manager Lite – Frontend Posting WordPress Plugin Security Vulnerabilities

CVEs by Year

1 CVE in 2024
2024
2 CVEs in 2025
2025
1 CVE in 2026
2026
Patched Has unpatched

Severity Breakdown

Medium
4

4 total CVEs

CVE-2026-1296medium · 6.1URL Redirection to Untrusted Site ('Open Redirect')

Frontend Post Submission Manager Lite <= 1.2.7 - Unauthenticated Open Redirect via 'requested_page' Parameter

Feb 17, 2026 Patched in 1.2.8 (1d)
CVE-2025-14913medium · 5.3Missing Authorization

Frontend Post Submission Manager Lite <= 1.2.6 - Incorrect Authorization to Unauthenticated Arbitrary Attachment Deletion

Dec 25, 2025 Patched in 1.2.7 (1d)
CVE-2025-14080medium · 5.3Missing Authorization

Frontend Post Submission Manager Lite <= 1.2.5 - Missing Authorization to Unauthenticated Arbitrary Post Modification

Dec 20, 2025 Patched in 1.2.6 (1d)
CVE-2024-8427medium · 4.3Missing Authorization

Frontend Post Submission Manager Lite – Frontend Posting WordPress Plugin <= 1.2.2 - Missing Authorization to Authenticated (Subscriber+) Settings Update

Sep 5, 2024 Patched in 1.2.3 (1d)
Code Analysis
Analyzed Mar 16, 2026

Frontend Post Submission Manager Lite – Frontend Posting WordPress Plugin Code Analysis

Dangerous Functions
0
Raw SQL Queries
4
8 prepared
Unescaped Output
37
482 escaped
Nonce Checks
5
Capability Checks
3
File Operations
2
External Requests
2
Bundled Libraries
0

SQL Query Safety

67% prepared12 total queries

Output Escaping

93% escaped519 total outputs
Data Flows
10 unsanitized

Data Flow Analysis

10 flows10 with unsanitized paths
save_global_settings (includes\classes\admin\class-fpsml-ajax-admin.php:96)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface
10 unprotected

Frontend Post Submission Manager Lite – Frontend Posting WordPress Plugin Attack Surface

Entry Points11
Unprotected10

AJAX Handlers 10

authwp_ajax_fpsml_form_edit_actionincludes\classes\admin\class-fpsml-ajax-admin.php:9
noprivwp_ajax_fpsml_form_edit_actionincludes\classes\admin\class-fpsml-ajax-admin.php:10
authwp_ajax_fpsml_settings_save_actionincludes\classes\admin\class-fpsml-ajax-admin.php:11
noprivwp_ajax_fpsml_settings_save_actionincludes\classes\admin\class-fpsml-ajax-admin.php:12
authwp_ajax_fpsml_file_upload_actionincludes\classes\class-fpsml-ajax.php:12
noprivwp_ajax_fpsml_file_upload_actionincludes\classes\class-fpsml-ajax.php:13
authwp_ajax_fpsml_media_delete_actionincludes\classes\class-fpsml-ajax.php:18
noprivwp_ajax_fpsml_media_delete_actionincludes\classes\class-fpsml-ajax.php:19
authwp_ajax_fpsml_form_processincludes\classes\class-fpsml-ajax.php:24
noprivwp_ajax_fpsml_form_processincludes\classes\class-fpsml-ajax.php:25

Shortcodes 1

[fpsm] includes\classes\class-fpsml-shortcode.php:8
WordPress Hooks 24
actionadmin_enqueue_scriptsincludes\classes\admin\class-fpsml-admin-enqueue.php:9
actionadmin_menuincludes\classes\admin\class-fpsml-admin.php:9
actionadmin_footerincludes\classes\admin\class-fpsml-admin.php:10
actionadmin_footerincludes\classes\admin\class-fpsml-admin.php:11
actionadd_meta_boxesincludes\classes\admin\class-fpsml-metabox.php:9
actionsave_postincludes\classes\admin\class-fpsml-metabox.php:10
actionadmin_initincludes\classes\admin\class-fpsml-review.php:6
actionadmin_post_fpsml_hide_review_noticeincludes\classes\admin\class-fpsml-review.php:7
actionadmin_noticesincludes\classes\admin\class-fpsml-review.php:22
actionwp_footerincludes\classes\class-fpsml-frontend-hooks.php:9
actionthe_contentincludes\classes\class-fpsml-frontend-hooks.php:11
actionthe_contentincludes\classes\class-fpsml-frontend-hooks.php:12
actiontemplate_redirectincludes\classes\class-fpsml-frontend-hooks.php:13
filterbody_classincludes\classes\class-fpsml-frontend-hooks.php:14
actioninitincludes\classes\class-fpsml-init.php:10
actionfpsml_form_submission_successincludes\classes\class-fpsml-notification.php:9
actionwp_trash_postincludes\classes\class-fpsml-notification.php:10
actiontransition_post_statusincludes\classes\class-fpsml-notification.php:12
actionwp_login_failedincludes\classes\class-fpsml-shortcode.php:9
filterauthenticateincludes\classes\class-fpsml-shortcode.php:10
actionlogin_formincludes\classes\class-fpsml-shortcode.php:11
filterlogin_form_middleincludes\classes\class-fpsml-shortcode.php:12
filterlogin_form_middleincludes\classes\class-fpsml-shortcode.php:13
filterauthenticateincludes\classes\class-fpsml-shortcode.php:14
Maintenance & Trust

Frontend Post Submission Manager Lite – Frontend Posting WordPress Plugin Maintenance & Trust

Maintenance Signals

WordPress version tested6.9.4
Last updatedFeb 11, 2026
PHP min version7.0
Downloads74K

Community Trust

Rating90/100
Number of ratings21
Active installs2K
Developer Profile

Frontend Post Submission Manager Lite – Frontend Posting WordPress Plugin Developer Profile

WP Shuffle

8 plugins · 4K total installs

99
trust score
Avg Security Score
98/100
Avg Patch Time
7 days
View full developer profile
Detection Fingerprints

How We Detect Frontend Post Submission Manager Lite – Frontend Posting WordPress Plugin

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/frontend-post-submission-manager-lite/assets/css/fpsml-backend-style.css/wp-content/plugins/frontend-post-submission-manager-lite/assets/fontawesome/css/all.min.css/wp-content/plugins/frontend-post-submission-manager-lite/assets/js/jquery.are-you-sure.js/wp-content/plugins/frontend-post-submission-manager-lite/assets/js/fpsml-backend.js/wp-content/plugins/frontend-post-submission-manager-lite/assets/css/fpsml-frontend-style.css/wp-content/plugins/frontend-post-submission-manager-lite/assets/css/fpsml-rtl-frontend-style.css/wp-content/plugins/frontend-post-submission-manager-lite/assets/font-face/NunitoSans/stylesheet.css/wp-content/plugins/frontend-post-submission-manager-lite/assets/font-face/comingsoon/stylesheet.css
Script Paths
/wp-content/plugins/frontend-post-submission-manager-lite/assets/js/jquery.are-you-sure.js/wp-content/plugins/frontend-post-submission-manager-lite/assets/js/fpsml-backend.js
Version Parameters
frontend-post-submission-manager-lite/assets/css/fpsml-backend-style.css?ver=frontend-post-submission-manager-lite/assets/fontawesome/css/all.min.css?ver=frontend-post-submission-manager-lite/assets/js/jquery.are-you-sure.js?ver=frontend-post-submission-manager-lite/assets/js/fpsml-backend.js?ver=frontend-post-submission-manager-lite/assets/css/fpsml-frontend-style.css?ver=frontend-post-submission-manager-lite/assets/css/fpsml-rtl-frontend-style.css?ver=frontend-post-submission-manager-lite/assets/font-face/NunitoSans/stylesheet.css?ver=frontend-post-submission-manager-lite/assets/font-face/comingsoon/stylesheet.css?ver=

HTML / DOM Fingerprints

CSS Classes
fpsml-preview-page
HTML Comments
<!-- FPSML -->
Data Attributes
data-fpsml-id
JS Globals
fpsml_backend_objfpsml_frontend_obj
Shortcode Output
[fpsm]
FAQ

Frequently Asked Questions about Frontend Post Submission Manager Lite – Frontend Posting WordPress Plugin