Back

MEDIUM

WordPress User Submitted Posts plugin <= 20260810 - Cross Site Scripting (XSS) vulnerability

Published Sep 30, 2026

Description

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Jeff Starr User Submitted Posts allows Stored XSS.

This issue affects User Submitted Posts: from n/a through 20260810.

Affected products

Remediation

Vendor solution

Update the WordPress User Submitted Posts Plugin to the latest available version (at least 20260916).

References (2)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner Patchstack
Published Sep 30, 2026
Updated Sep 30, 2026
Reserved Jul 13, 2026
CISA Vulnrichment
Updated Sep 30, 2026
NVD
Status Received
Modified Sep 30, 2026
Red Hat
Severity n/a
Public date n/a
ENISA EUVD
Assigner Patchstack
Published Sep 30, 2026
Updated Sep 30, 2026
Exploited since n/a
EUVD-2026-89958