CVE-2016-11001: XSS
Published Sep 20, 2019
·Updated
The user-submitted-posts plugin before 20160215 for WordPress has XSS via the user-submitted-content field.
Affected Software
1 affected component
Plugin-planet User Submitted Posts Wordpress<20160215
Event History
Sep 20, 2019
CVE Published
via MITRE·02:35 PM
Data Sourced
via MITRE·02:35 PM
Description
Frequently Asked Questions
1
What is the vulnerability ID for this WordPress plugin issue?
The vulnerability ID for this WordPress plugin issue is CVE-2016-11001.
2
What is the severity of CVE-2016-11001?
The severity of CVE-2016-11001 is medium.
3
How does CVE-2016-11001 impact WordPress?
CVE-2016-11001 allows for XSS attacks in WordPress through the user-submitted-content field.
4
Is there a fix for CVE-2016-11001?
Yes, a fix for CVE-2016-11001 is available in version 20160215 of the user-submitted-posts plugin for WordPress.
5
Where can I find more information about CVE-2016-11001?
More information about CVE-2016-11001 can be found at wordpress.org/plugins/user-submitted-posts/#developers and securityfocus.com/archive/1/537616/30/0/threaded.