CVE-2025-14913
Unknown
Unknown - Not Provided
Authorization Bypass in Frontend Post Submission Lite Allows Data Deletion
Publication date: 2025-12-26
Last updated on: 2025-12-26
Assigner: Wordfence
Description
Description
The Frontend Post Submission Manager Lite β Frontend Posting WordPress Plugin plugin for WordPress is vulnerable to unauthorized loss of data due to an incorrect authorization check on the 'media_delete_action' function in all versions up to, and including, 1.2.6. This makes it possible for unauthenticated attackers to delete arbitrary attachments.
CVSS Scores
EPSS Scores
| Probability: | |
| Percentile: |
Meta Information
Affected Vendors & Products
| Vendor | Product | Version / Range |
|---|---|---|
| wordfence | frontend_post_submission_manager_lite | 1.2.6 |
Helpful Resources
Exploitability
| CWE ID | Description |
|---|---|
| CWE-862 | The product does not perform an authorization check when an actor attempts to access a resource or perform an action. |