CVE-2026-1296
Last modified
CVE-2026-1296 is a medium-severity vulnerability rated 6.1/10 on the CVSS scale. The Frontend Post Submission Manager Lite plugin for WordPress is vulnerable to Open Redirection in all versions up to, and including, 1.2.7 due to insufficient validation on the 'requested_page' POST parameter in the verify_username_password function. This makes it possible for unauthenticated attackers to redirect users to potentially malicious sites if they can successfully trick them into performing an action such as clicking on a link.. EPSS estimates a 0.46% chance of exploitation in the next 30 days.
Description
The Frontend Post Submission Manager Lite plugin for WordPress is vulnerable to Open Redirection in all versions up to, and including, 1.2.7 due to insufficient validation on the 'requested_page' POST parameter in the verify_username_password function. This makes it possible for unauthenticated attackers to redirect users to potentially malicious sites if they can successfully trick them into performing an action such as clicking on a link.
Metrics
Weakness Enumeration
References
Timeline
- Published
- Last Modified
- Status
- Deferred
Frequently Asked Questions
What is CVE-2026-1296?
How severe is CVE-2026-1296?
How do I fix CVE-2026-1296?
How Strix Helps
- One Click Account Takeover in GranolaHow a notification link broke out of Electron and led to a one-click account takeover.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2026
- CVE-2026-1295The Buy Now Plus – Buy Now buttons for Stripe plugin for Wor…6.4
- CVE-2026-12954The Mapster WP Maps plugin for WordPress is vulnerable to Ar…8.8
- CVE-2026-12955The GDPR Cookie Consent plugin for WordPress is vulnerable t…4.3
- CVE-2026-12956The WP Event Solution (Eventin) plugin for WordPress is vuln…5.3
- CVE-2026-12957Improper trust boundary enforcement in Language Servers for …8.5
- CVE-2026-12958Missing symlink validation in Language Servers for AWS may a…8.5
- CVE-2026-12960An Improper Export of Android Application Components vulnera…6
- CVE-2026-12962A Permissive Cross-domain Security Policy with Untrusted Dom…5.3
- CVE-2026-12965The Super Store Finder WordPress plugin before 7.11 does not…9.1
- CVE-2026-12966The Direct Payments for WooCommerce WordPress plugin before…5.3
- CVE-2026-12968The Product Addons and Product Options With Custom Fields W…8.8
- CVE-2026-12969An out-of-bounds read vulnerability exists in dnsmasq's find…5.3
Are you affected by CVE-2026-1296?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
