PT-2026-54496 · WordPress · User Submitted Posts

·

CVE-2026-11570

·

Published

2026-07-01

·

Updated

2026-07-01

CVSS v3.1

4.2

Medium

VectorAV:N/AC:H/PR:N/UI:R/S:U/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions User Submitted Posts versions prior to 20260608
Description Stored Cross-Site Scripting occurs when the plugin fails to escape a submitted value before outputting it in an admin-configured display template. This issue can be triggered by unauthenticated users provided that a non-default display option is enabled.
Recommendations Update User Submitted Posts to version 20260608 or later.

Exploit

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2026-11570

Affected Products

User Submitted Posts