CVE-2022-4946: Accesspressthemes Frontend Post WordPress Plugin

Medium severity, CVSS 5.4. EPSS: 0.4% chance of exploitation in the next 30 days.

The Frontend Post WordPress Plugin WordPress plugin through 2.8.4 does not validate an attribute of one of its shortcode, which could allow users with a role as low as contributor to add a malicious shortcode to a page/post, which will redirect users to an arbitrary domain.

Affected products

Published 2023-06-05. Last modified 2026-06-17.