Description
The Frontend Post Submission Manager Lite plugin for WordPress is vulnerable to Open Redirection in all versions up to, and including, 1.2.7 due to insufficient validation on the 'requested_page' POST parameter in the verify_username_password function. This makes it possible for unauthenticated attackers to redirect users to potentially malicious sites if they can successfully trick them into performing an action such as clicking on a link.
Problem types
CWE-601 URL Redirection to Untrusted Site ('Open Redirect')
Product status
1.0.0 (semver)
Timeline
| 2026-01-21: | Vendor Notified |
| 2026-02-17: | Disclosed |
Credits
Kenneth Dunn
References
www.wordfence.com/...-7cf5-4a1b-80a1-b01140e6a72b?source=cve
plugins.trac.wordpress.org/...sses/class-fpsml-shortcode.php
plugins.trac.wordpress.org/...sses/class-fpsml-shortcode.php
plugins.trac.wordpress.org/...ger-lite&sfp_email=&sfph_mail=