CVE-2022-4946: Accesspressthemes Frontend Post WordPress Plugin
Medium severity, CVSS 5.4. EPSS: 0.4% chance of exploitation in the next 30 days.
The Frontend Post WordPress Plugin WordPress plugin through 2.8.4 does not validate an attribute of one of its shortcode, which could allow users with a role as low as contributor to add a malicious shortcode to a page/post, which will redirect users to an arbitrary domain.
Affected products
- Accesspressthemes Frontend Post WordPress Plugin: up to and including 2.8.4
Published 2023-06-05. Last modified 2026-06-17.