
Frontend Post Submission Manager Lite – Frontend Posting WordPress Plugin Security & Risk Analysis
wordpress.org/plugins/frontend-post-submission-manager-liteFrontend Post Submission with or without Login, 5 PreDesigned Form Templates, Add Unlimited Custom Fields, Google Captcha Security, Post Notifications
Is Frontend Post Submission Manager Lite – Frontend Posting WordPress Plugin Safe to Use in 2026?
Generally Safe
Score 95/100Frontend Post Submission Manager Lite – Frontend Posting WordPress Plugin has a strong security track record. Known vulnerabilities have been patched promptly.
The plugin 'frontend-post-submission-manager-lite' v1.2.8 exhibits a concerning security posture, primarily due to a significant number of unprotected entry points. While the plugin demonstrates good practices in areas like output escaping (93% properly escaped) and SQL prepared statements (67%), the presence of 10 AJAX handlers lacking authentication checks is a major vulnerability. This broad attack surface without proper authorization could allow unauthenticated users to trigger potentially sensitive actions.
The taint analysis further amplifies these concerns, revealing 8 high-severity flows with unsanitized paths. This suggests that user-supplied data might be improperly handled, leading to potential code execution or unauthorized access. While no critical taint flows were identified, the high number of high-severity ones remains a significant risk. The plugin's vulnerability history, with 4 medium-severity CVEs in the past, predominantly related to 'Open Redirect' and 'Missing Authorization', reinforces the pattern of authorization weaknesses.
Despite the robust output escaping and SQL practices, the sheer volume of unprotected AJAX endpoints and the critical taint analysis findings present a substantial risk. The past vulnerabilities indicate a recurring issue with authorization, which appears to be a fundamental weakness in this plugin. Users should exercise extreme caution and consider delaying updates or seeking alternative solutions until these authorization and taint flow issues are addressed.
Key Concerns
- 10 unprotected AJAX handlers
- 8 high severity taint flows
- 4 medium severity CVEs historically
- 6 SQL queries without prepared statements
- 2 file operations
- 2 external HTTP requests
- 3 capability checks vs 10 unprotected AJAX handlers
Frontend Post Submission Manager Lite – Frontend Posting WordPress Plugin Security Vulnerabilities
CVEs by Year
Severity Breakdown
4 total CVEs
Frontend Post Submission Manager Lite <= 1.2.7 - Unauthenticated Open Redirect via 'requested_page' Parameter
Frontend Post Submission Manager Lite <= 1.2.6 - Incorrect Authorization to Unauthenticated Arbitrary Attachment Deletion
Frontend Post Submission Manager Lite <= 1.2.5 - Missing Authorization to Unauthenticated Arbitrary Post Modification
Frontend Post Submission Manager Lite – Frontend Posting WordPress Plugin <= 1.2.2 - Missing Authorization to Authenticated (Subscriber+) Settings Update
Frontend Post Submission Manager Lite – Frontend Posting WordPress Plugin Code Analysis
SQL Query Safety
Output Escaping
Data Flow Analysis
Frontend Post Submission Manager Lite – Frontend Posting WordPress Plugin Attack Surface
AJAX Handlers 10
Shortcodes 1
WordPress Hooks 24
Maintenance & Trust
Frontend Post Submission Manager Lite – Frontend Posting WordPress Plugin Maintenance & Trust
Maintenance Signals
Community Trust
Frontend Post Submission Manager Lite – Frontend Posting WordPress Plugin Alternatives
Easy Post Submission – Frontend Posting, Guest Publishing & Submit Content for WordPress
easy-post-submission
Enable users to submit posts and manage profiles from the front-end. Ideal for news, magazines, and creative platforms.
BigIdeas
bigideas
Allows a user to post an idea to an Ideas page at /Ideas/. A BuddyPress group with bbPress forum are automatically created when this post is published …
Frontend Admin by DynamiApps
acf-frontend-form-element
This awesome plugin allows you to easily display frontend forms on your site so your clients can easily edit content by themselves from the frontend.
Guest posting / Frontend Posting / Front Editor – WP Front User Submit
front-editor
This plugin enables users to submit post content from Front End. Use our plugin to implement guest posting
WP User Frontend Integration for Ultimate Member
um-wp-user-frontend
Allows adding WP User Frontend's post form into Ultimate member's profile tab.
Frontend Post Submission Manager Lite – Frontend Posting WordPress Plugin Developer Profile
8 plugins · 4K total installs
How We Detect Frontend Post Submission Manager Lite – Frontend Posting WordPress Plugin
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/frontend-post-submission-manager-lite/assets/css/fpsml-backend-style.css/wp-content/plugins/frontend-post-submission-manager-lite/assets/fontawesome/css/all.min.css/wp-content/plugins/frontend-post-submission-manager-lite/assets/js/jquery.are-you-sure.js/wp-content/plugins/frontend-post-submission-manager-lite/assets/js/fpsml-backend.js/wp-content/plugins/frontend-post-submission-manager-lite/assets/css/fpsml-frontend-style.css/wp-content/plugins/frontend-post-submission-manager-lite/assets/css/fpsml-rtl-frontend-style.css/wp-content/plugins/frontend-post-submission-manager-lite/assets/font-face/NunitoSans/stylesheet.css/wp-content/plugins/frontend-post-submission-manager-lite/assets/font-face/comingsoon/stylesheet.css/wp-content/plugins/frontend-post-submission-manager-lite/assets/js/jquery.are-you-sure.js/wp-content/plugins/frontend-post-submission-manager-lite/assets/js/fpsml-backend.jsfrontend-post-submission-manager-lite/assets/css/fpsml-backend-style.css?ver=frontend-post-submission-manager-lite/assets/fontawesome/css/all.min.css?ver=frontend-post-submission-manager-lite/assets/js/jquery.are-you-sure.js?ver=frontend-post-submission-manager-lite/assets/js/fpsml-backend.js?ver=frontend-post-submission-manager-lite/assets/css/fpsml-frontend-style.css?ver=frontend-post-submission-manager-lite/assets/css/fpsml-rtl-frontend-style.css?ver=frontend-post-submission-manager-lite/assets/font-face/NunitoSans/stylesheet.css?ver=frontend-post-submission-manager-lite/assets/font-face/comingsoon/stylesheet.css?ver=HTML / DOM Fingerprints
fpsml-preview-page<!-- FPSML -->data-fpsml-idfpsml_backend_objfpsml_frontend_obj[fpsm]