PT-2025-52576 · WordPress · Frontend Post Submission Manager Lite

Md. Moniruzzaman Prodhan

+1

·

Published

2025-12-21

·

Updated

2025-12-21

·

CVE-2025-14080

CVSS v3.1

5.3

Medium

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
Name of the Vulnerable Software and Affected Versions Frontend Post Submission Manager Lite plugin versions through 1.2.5
Description The Frontend Post Submission Manager Lite plugin for WordPress has an issue where authorization checks are missing on the post update functionality within the fpsml form process AJAX action. This allows unauthenticated attackers to modify posts by providing a post id parameter through the guest posting form. Attackers can change post titles, content, and excerpts, and remove post authors. The vulnerable parameter is post id.
Recommendations Update the Frontend Post Submission Manager Lite plugin to a version later than 1.2.5.

Fix

Missing Authorization

Weakness Enumeration

Related Identifiers

CVE-2025-14080

Affected Products

Frontend Post Submission Manager Lite