PT-2026-54496 · WordPress · User Submitted Posts
CVSS v3.1
4.2
Medium
| Vector | AV:N/AC:H/PR:N/UI:R/S:U/C:L/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
User Submitted Posts versions prior to 20260608
Description
Stored Cross-Site Scripting occurs when the plugin fails to escape a submitted value before outputting it in an admin-configured display template. This issue can be triggered by unauthenticated users provided that a non-default display option is enabled.
Recommendations
Update User Submitted Posts to version 20260608 or later.
Exploit
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
User Submitted Posts