First published: Fri Sep 20 2019(Updated: )
The user-submitted-posts plugin before 20160215 for WordPress has XSS via the user-submitted-content field.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Plugin-Planet User Submitted Posts | <20160215 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID for this WordPress plugin issue is CVE-2016-11001.
The severity of CVE-2016-11001 is medium.
CVE-2016-11001 allows for XSS attacks in WordPress through the user-submitted-content field.
Yes, a fix for CVE-2016-11001 is available in version 20160215 of the user-submitted-posts plugin for WordPress.
More information about CVE-2016-11001 can be found at wordpress.org/plugins/user-submitted-posts/#developers and securityfocus.com/archive/1/537616/30/0/threaded.