CVE-2026-62084: WordPress User Submitted Posts plugin <= 20260810 - Cross Site Scripting (XSS) vulnerability
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Jeff Starr User Submitted Posts allows Stored XSS.
This issue affects User Submitted Posts: from n/a through 20260810.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
WordPress User Submitted Posts Pluginto a version that resolves this vulnerability.Fixed in 20260916
Event History
Frequently Asked Questions
What level of access and interaction are required to exploit this issue?
The vector indicates network exploitation with low attack complexity, but the attacker needs low-level privileges and a user must interact with the malicious content. Successful exploitation can affect confidentiality, integrity, and availability beyond the vulnerable component.
Which plugin versions are affected?
User Submitted Posts versions through 20260810 are affected. The supplied data does not identify a fixed version.