S4E just found a high-severity finding from top 10 tcp port service scan
PlatformPlansPartners
Resources
ToolsBlogDocs
Sign Up →
medium·Product Based Web Vulnerabilities·Updated Mar 17, 2026

CVE-2026-1296 Scanner

CVE-2026-1296 Scanner - Open Redirect vulnerability in Frontend Post Submission Manager Lite (WordPress)

Est. Time~10 seconds
Scan TypeSingle Scan
Targetsdomain, subdomain, ipv4
CostFree
3.5k
Times Used
continuous scan runs
5.5k
Continuously Checked
assets under CS
0
Vulnerabilities Found
confirmed findings
References
CVECVE-2026-1296
6.1
CVSSmedium
Exploitable remotely over the internet · no authentication required · user interaction needed.

The Frontend Post Submission Manager Lite plugin for WordPress is vulnerable to Open Redirection in all versions up to, and including, 1.2.7 due to insufficient validation on the 'requested_page' POST parameter in the verify_username_password function. This makes it possible for unauthenticated attackers to redirect users to potentially malicious sites if they can successfully trick them into performing an action such as clicking on a link.

Attack Vector
Network
Privileges Req.
None
User Interaction
Required
Affected
Frontend Post Submission Manager Lite – Frontend Posting WordPress Pluginby wpshuffle
1.0.0
Updated Aug 22, 2026View on NVD →
Detail

The Frontend Post Submission Manager Lite is a WordPress plugin designed for users who need to manage front-end content submissions effectively. Its user-friendly interface allows website administrators to handle content submission workflows without complicated backend interactions. The plugin is widely used in content-focused websites and blogging platforms where there is a need to manage contributions from multiple authors. Administrators can set up custom post types and manage user submissions all from the front end. Users value it for its simplicity and capability to streamline content management. Popular across various WordPress sites, it's aimed at enhancing the flexibility and efficiency of content handling.

An open redirect vulnerability in Frontend Post Submission Manager Lite allows unauthenticated attackers to manipulate URL redirects. This vulnerability can be exploited via insufficient validation of the 'requested_page' POST parameter, enabling unauthorized redirects. The impact includes potential phishing and exposure to malicious sites if users are tricked into clicking deceptive links. Such redirection flaws are often exploited in social engineering attacks. It's crucial to address this to prevent unauthorized redirections to harmful destinations. The CVE-2026-1296 reference provides further details on this vulnerability.

The open redirect issue in Frontend Post Submission Manager Lite arises from improper validation of the 'requested_page' parameter. The vulnerability can be triggered via HTTP POST requests, specifically targeting the /wp-login.php endpoint. Attackers craft requests directing users to arbitrary destinations, leveraging the insufficient handling of input parameters. The HTTP status code 302 response signals a redirection, which can be checked by analyzing response headers. Exploiting this allows attackers to redirect genuine users to malicious sites without authorization. Monitoring and filtering parameter values can mitigate this risk.

Exploitation of this vulnerability can lead to end-users being redirected to phishing sites or other malicious pages. This poses risks such as credential theft, exposure to malware, and loss of sensitive data. Attackers can gain trust under false pretenses, potentially accessing personal or financial information. The redirection exploits might further facilitate larger-scale attacks by amassing victim data through bait sites. Prompt remediation reduces the risk of users being deceived into interacting with unauthorized resources, preserving user trust and site integrity.

REFERENCES

Solution Advice
  • Update to a version later than 1.2.7 or the latest available version.
  • Implement input validation checks on the 'requested_page' parameter to prevent unauthorized URLs.
  • Monitor server logs for unusual redirect patterns and unauthorized access attempts.
  • Educate users about potential phishing tactics and encourage them to scrutinize unexpected redirect links.
  • Ensure that all redirects are logged and regularly audit them for potential abuses.

Get AI-powered remediation steps tailored to your asset.

Try AI Solutions →

Check your infrastructure.
Right now.

11,000+ scanners. Free to start. No credit card required.