Impact
The User Submitted Posts plugin for WordPress is vulnerable to stored cross‑site scripting in all releases up to and including 20260110. The flaw stems from insufficient sanitization and escaping of attributes passed to the ‘usp_access’ shortcode. Consequently, authenticated contributors or higher can insert arbitrary JavaScript into any page that renders the shortcode, leading to defacement, credential theft, or distribution of malware when other users view the page.
Affected Systems
The affected product is the WordPress plugin User Submitted Posts by specialk. All versions up to and including 20260110 are impacted. Content owners who rely on this plugin for front‑end post submission and allow Contributor access should assume the vulnerability is present unless the plugin has been upgraded beyond 20260110.
Risk and Exploitability
The vulnerability scores a 6.4 on the CVSS framework, indicating a moderate to high risk, while the EPSS score is below 1%, suggesting low current exploitation probability. It is not listed in the CISA KEV catalogue. Exploitation requires an authenticated account with Contributor or higher privileges and the use of the ‘usp_access’ shortcode. An attacker can embed malicious scripts that will run in the browsers of any user who visits the affected page.
OpenCVE Enrichment