plugin

User Submitted Posts Vulnerabilities

26 known security issues reported for the User Submitted Posts WordPress plugin. Most recent disclosed Feb 17, 2026.

2 critical 3 high 7 medium

Running User Submitted Posts on your site? Check whether your installed version is affected.

Scan your site free

User Submitted Posts <= 20260113 - Incorrect Authorization to Unauthenticated Category Restriction Bypass via 'user-submitted-category' Parameter

medium

The User Submitted Posts – Enable Users to Submit Posts from the Front End plugin for WordPress is vulnerable to Incorrect Authorization in all versions up to, and including, 20260113. This is due to the `usp_get_submitted_category()` function accepting user-submitted category IDs from the POST body without validating...

CVSS:
5.3
Affected:
up to 20260113
Fixed in:
20260217
Disclosed:
Feb 17, 2026

CVE-2026-2126 on NVD →

User Submitted Posts – Enable Users to Submit Posts from the Front End <= 20251210 - Unauthenticated Stored Cross-Site Scripting via Custom Field

high

The User Submitted Posts – Enable Users to Submit Posts from the Front End plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the custom fields in all versions up to, and including, 20251210 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attacke...

CVSS:
7.2
Affected:
up to 20251210
Fixed in:
20260110
Disclosed:
Jan 23, 2026

CVE-2026-0800 on NVD →

User Submitted Posts <= 20260110 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'usp_access' Shortcode

medium

The User Submitted Posts – Enable Users to Submit Posts from the Front End plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'usp_access' shortcode in all versions up to, and including, 20260110 due to insufficient input sanitization and output escaping on user supplied attributes. This...

CVSS:
6.4
Affected:
up to 20260110
Fixed in:
20260113
Disclosed:
Jan 15, 2026

CVE-2026-0913 on NVD →

User Submitted Posts <= 20251121 - Unauthenticated Open Redirect

medium

The User Submitted Posts – Enable Users to Submit Posts from the Front End plugin for WordPress is vulnerable to Open Redirect in all versions up to, and including, 20251121. This is due to insufficient validation on the redirect url supplied parameter. This makes it possible for unauthenticated attackers to redirect u...

CVSS:
5.3
Affected:
up to 20251121
Fixed in:
20251210
Disclosed:
Jan 1, 2026

CVE-2025-68509 on NVD →

User Submitted Posts – Enable Users to Submit Posts from the Front End [user-submitted-posts] <= 20251121 (unfixed)

unknown

[en] URL Redirection to Untrusted Site ('Open Redirect') vulnerability in Jeff Starr User Submitted Posts user-submitted-posts allows Phishing.This issue affects User Submitted Posts: from n/a through <= 20251121.

Affected:
up to 20251121
Fix:
No patched version reported
Disclosed:
Dec 24, 2025

CVE-2025-68509 on NVD →

User Submitted Posts <= 20241026 - Authenticated (Admin+) Stored Cross-Site Scripting

medium

The User Submitted Posts – Enable Users to Submit Posts from the Front End plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and including, 20240319 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, w...

CVSS:
4.4
Affected:
up to 20241026
Fixed in:
20250327
Disclosed:
Apr 2, 2025

CVE-2025-2874 on NVD →

User Submitted Posts – Enable Users to Submit Posts from the Front End [user-submitted-posts] < 20240516

unknown

[en] The User Submitted Posts WordPress plugin before 20240516 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)

Affected:
up to 20240516
Fixed in:
20240516
Disclosed:
Jul 13, 2024

CVE-2024-5002 on NVD →

User Submitted Posts – Enable Users to Submit Posts from the Front End <= 20240319 - Authenticated (Admin+) Stored Cross-Site Scripting

medium

The User Submitted Posts – Enable Users to Submit Posts from the Front End plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and including, 20240319 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, w...

CVSS:
4.4
Affected:
up to 20240319
Fixed in:
20240516
Disclosed:
Jun 22, 2024

CVE-2024-5002 on NVD →

User Submitted Posts – Enable Users to Submit Posts from the Front End [user-submitted-posts] < 20230902

unknown

[en] Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Jeff Starr User Submitted Posts allows Stored XSS.This issue affects User Submitted Posts: from n/a through 20230901.

Affected:
up to 20230902
Fixed in:
20230902
Disclosed:
Mar 26, 2024

CVE-2023-7251 on NVD →

User Submitted Posts – Enable Users to Submit Posts from the Front End [user-submitted-posts] < 20230902

unknown
Affected:
up to 20230902
Fixed in:
20230902
Disclosed:
Mar 26, 2024

CVE-2023-41696 on NVD →

User Submitted Posts – Enable Users to Submit Posts from the Front End [user-submitted-posts] < 20230914

unknown

[en] Unrestricted Upload of File with Dangerous Type vulnerability in Jeff Starr User Submitted Posts – Enable Users to Submit Posts from the Front End.This issue affects User Submitted Posts – Enable Users to Submit Posts from the Front End: from n/a through 20230902.

Affected:
up to 20230914
Fixed in:
20230914
Disclosed:
Dec 20, 2023

CVE-2023-45603 on NVD →

User Submitted Posts <= 20230902 - Unauthenticated Arbitrary File Upload

critical

The User Submitted Posts plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the usp_attach_images function in versions up to, and including, 20230902. This makes it possible for unauthenticatedattackers to upload arbitrary files as long as the extension does not contain...

CVSS:
9.8
Affected:
up to 20230902
Fixed in:
20230914
Disclosed:
Oct 10, 2023

CVE-2023-45603 on NVD →

User Submitted Posts <= 20230901 - Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode

medium

The User Submitted Posts plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's shortcodes in versions up to, and including, 20230901 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above, to in...

CVSS:
6.4
Affected:
up to 20230901
Fixed in:
20230902
Disclosed:
Sep 6, 2023

CVE-2023-7251 on NVD →

User Submitted Posts – Enable Users to Submit Posts from the Front End [user-submitted-posts] < 20230901

unknown

[en] The User Submitted Posts plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's [usp_gallery] shortcode in versions up to, and including, 20230811 due to insufficient input sanitization and output escaping on user supplied attributes like 'before'. This makes it possible for authenticat...

Affected:
up to 20230901
Fixed in:
20230901
Disclosed:
Sep 6, 2023

CVE-2023-4779 on NVD →

User Submitted Posts – Enable Users to Submit Posts from the Front End <= 20230811 - Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode

medium

The User Submitted Posts plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's [usp_gallery] shortcode in versions up to, and including, 20230811 due to insufficient input sanitization and output escaping on user supplied attributes like 'before'. This makes it possible for authenticated at...

CVSS:
6.4
Affected:
up to 20230811
Fixed in:
20230901
Disclosed:
Sep 5, 2023

CVE-2023-4779 on NVD →

User Submitted Posts – Enable Users to Submit Posts from the Front End [user-submitted-posts] < 20230811

unknown

[en] The User Submitted Posts plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘user-submitted-content’ parameter in versions up to, and including, 20230809 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web s...

Affected:
up to 20230811
Fixed in:
20230811
Disclosed:
Aug 15, 2023

CVE-2023-4308 on NVD →

User Submitted Posts <= 20230809 - Unauthenticated Stored Cross-Site Scripting via 'user-submitted-content'

high

The User Submitted Posts plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘user-submitted-content’ parameter in versions up to, and including, 20230809 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web script...

CVSS:
7.2
Affected:
up to 20230809
Fixed in:
20230811
Disclosed:
Aug 14, 2023

CVE-2023-4308 on NVD →

User Submitted Posts – Enable Users to Submit Posts from the Front End [user-submitted-posts] < 20190426

unknown

[en] The User Submitted Posts plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the usp_check_images function in versions up to, and including, 20190312. This makes it possible for unauthenticated attackers to upload arbitrary files on the affected sites server which ma...

Affected:
up to 20190426
Fixed in:
20190426
Disclosed:
Jun 7, 2023

CVE-2019-25138 on NVD →

User Submitted Posts – Enable Users to Submit Posts from the Front End [user-submitted-posts] < 20160215

unknown

[en] The user-submitted-posts plugin before 20160215 for WordPress has XSS via the user-submitted-content field.

Affected:
up to 20160215
Fixed in:
20160215
Disclosed:
Sep 20, 2019

CVE-2016-11001 on NVD →

User Submitted Posts – Enable Users to Submit Posts from the Front End [user-submitted-posts] < 20190501

unknown

Arbitrary File Upload vulnerability found by NinTechNet in WordPress User Submitted Posts plugin (versions <= 20190426). Apache + PHP FastCGI required for exploitation of this vulnerability.

Affected:
up to 20190501
Fixed in:
20190501
Disclosed:
Jun 11, 2019

User Submitted Posts <= 20190312 - Unauthenticated Arbitrary File Upload

critical

The User Submitted Posts plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the usp_check_images function in versions up to, and including, 20190312. This makes it possible for unauthenticated attackers to upload arbitrary files on the affected sites server which may mak...

CVSS:
9.8
Affected:
up to 20190426
Fixed in:
20190426
Disclosed:
May 2, 2019

CVE-2019-25138 on NVD →

User Submitted Posts – Enable Users to Submit Posts from the Front End [user-submitted-posts] < 20190426

unknown

The User Submitted Posts plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the usp_check_images function in versions up to, and including, 20190312. This makes it possible for unauthenticated attackers to upload arbitrary files on the affected sites server which may mak...

Affected:
up to 20190426
Fixed in:
20190426
Disclosed:
May 2, 2019

User Submitted Posts – Enable Users to Submit Posts from the Front End [user-submitted-posts] < 20160215

unknown

Because of this vulnerability, users with "unfiltered_html" capability are allowed to include JS code to post content. Update the plugin.

Affected:
up to 20160215
Fixed in:
20160215
Disclosed:
Feb 25, 2016

User Submitted Posts < 20160215 - Reflected Cross-Site Scripting

high

The user-submitted-posts plugin before 20160215 for WordPress has XSS via the user-submitted-content field.

CVSS:
7.2
Affected:
up to 20160215
Fixed in:
20160215
Disclosed:
Feb 10, 2016

CVE-2016-11001 on NVD →

User Submitted Posts – Enable Users to Submit Posts from the Front End [user-submitted-posts] < 20190501

unknown
Affected:
up to 20190501
Fixed in:
20190501

User Submitted Posts – Enable Users to Submit Posts from the Front End [user-submitted-posts] < 20250327

unknown
Affected:
up to 20250327
Fixed in:
20250327

CVE-2025-2874 on NVD →

Protect your WordPress site

Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.

Scan your site free

← Back to the vulnerability database