Subscriptions
Tracking
Sign in to view the affected projects.
No advisories yet.
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
Thu, 19 Feb 2026 10:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Specialk
Specialk user Submitted Posts – Enable Users To Submit Posts From The Front End Wordpress Wordpress wordpress |
|
| Vendors & Products |
Specialk
Specialk user Submitted Posts – Enable Users To Submit Posts From The Front End Wordpress Wordpress wordpress |
Wed, 18 Feb 2026 13:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Wed, 18 Feb 2026 09:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | The User Submitted Posts – Enable Users to Submit Posts from the Front End plugin for WordPress is vulnerable to Incorrect Authorization in all versions up to, and including, 20260113. This is due to the `usp_get_submitted_category()` function accepting user-submitted category IDs from the POST body without validating them against the admin-configured allowed categories stored in `usp_options['categories']`. This makes it possible for unauthenticated attackers to assign submitted posts to arbitrary categories, including restricted ones, by crafting a direct POST request with manipulated `user-submitted-category[]` values, bypassing the frontend category restrictions. | |
| Title | User Submitted Posts <= 20260113 - Incorrect Authorization to Unauthenticated Category Restriction Bypass via 'user-submitted-category' Parameter | |
| Weaknesses | CWE-863 | |
| References |
|
|
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: Wordfence
Published:
Updated: 2026-02-18T12:51:09.152Z
Reserved: 2026-02-06T18:37:48.354Z
Link: CVE-2026-2126
Updated: 2026-02-18T12:26:22.237Z
Status : Awaiting Analysis
Published: 2026-02-18T10:16:15.173
Modified: 2026-02-18T17:51:53.510
Link: CVE-2026-2126
No data.
OpenCVE Enrichment
Updated: 2026-02-19T10:20:29Z