Impact
The flaw exists because the User Submitted Posts plugin does not escape values entered in the author name field before rendering them in an admin‑configured an attacker is stored in the database and later executed when any user views the rendered page. The vulnerability is a classic Cross‑Site Scripting weakness identified as CWE‑79 and can affect the confidentiality and integrity of users who load the compromised content.
Affected Systems
WordPress installations that have the User Submitted Posts plugin installed at a revision earlier than 20260608 are susceptible. No other vendors or products are listed by the CNA data. The 20260608 release fixes the issue when the plugin’s non‑default display option is enabled.
Risk and Exploitability
The CVSS score of 4.2 indicates moderate severity, while the EPSS score of < 1% signals a very low probability of exploitation at this time. The vulnerability is not listed in CISA’s KEV catalog. Based on the description, the likely attack vector is an unauthenticated web request that submits a post with a malicious author name; the resulting payload is stored in the database and then executed whenever any user views the affected post.
OpenCVE Enrichment