Impact
The vulnerability is an improper neutralization of input during web page generation that permits stored cross‑site scripting. An attacker can inject malicious scripts into a post submitted through the WordPress User Submitted Posts plugin, and those scripts will execute in the browsers of any visitor to the affected site. The impact can include session hijacking, defacement, or the delivery of malware to site users, reflecting the classic Cross‑Site Scripting weakness identified as CWE‑79.
Affected Systems
The flaw is present in the Jeff Starr "User Submitted Posts" plugin for WordPress. All released versions from the unversioned initial release up through 20260810 are affected. Owners of WordPress sites that have this plugin installed should verify the version and upgrade if necessary.
Risk and Exploitability
The CVSS score of 6.5 categorizes the issue as moderate severity. No EPSS score is currently available, but the lack of exploitation data combined with the broad user base of WordPress suggests a low to moderate likelihood of exploitation. The vulnerability is not listed in the CISA KEV catalog. Attackers would need to submit a maliciously crafted post that the plugin stores without proper sanitization, which is feasible for anyone with write access to the plugin’s content creation interface.
OpenCVE Enrichment