Extension WordPress

Vulnérabilités User Submitted Posts – Enable Users to Submit Posts from the Front End

Cette page rassemble les failles publiées pour User Submitted Posts – Enable Users to Submit Posts from the Front End, leurs plages de versions affectées et les correctifs signalés dans la base locale.

12Vulnérabilités
2Critiques
12Avec correctif
9,8CVSS maximal

Historique de sécurité

CVE et vulnérabilités de User Submitted Posts – Enable Users to Submit Posts from the Front End

12 fiches

CVE-2026-2126 Moyenne · 5,3
User Submitted Posts – Enable Users to Submit Posts from the Front End

User Submitted Posts <= 20260113 – Incorrect Authorization to Unauthenticated Category Restriction Bypass via 'user-submitted-category' Parameter

The User Submitted Posts – Enable Users to Submit Posts from the Front End plugin for WordPress is vulnerable to Incorrect Authorization in all versions up to, and including, 20260113. This is due to the `usp_get_submitted_category()` function accepting…

Versions affectées

*-20260113

Correctif

20260217

Publication

17/02/2026

CVE-2026-0800 Élevée · 7,2
User Submitted Posts – Enable Users to Submit Posts from the Front End

User Submitted Posts – Enable Users to Submit Posts from the Front End <= 20251210 – Unauthenticated Stored Cross-Site Scripting via Custom Field

The User Submitted Posts – Enable Users to Submit Posts from the Front End plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the custom fields in all versions up to, and including, 20251210 due to insufficient…

Versions affectées

*-20251210

Correctif

20260110

Publication

23/01/2026

CVE-2026-0913 Moyenne · 6,4
User Submitted Posts – Enable Users to Submit Posts from the Front End

User Submitted Posts <= 20260110 – Authenticated (Contributor+) Stored Cross-Site Scripting via 'usp_access' Shortcode

The User Submitted Posts – Enable Users to Submit Posts from the Front End plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'usp_access' shortcode in all versions up to, and including, 20260110 due to…

Versions affectées

*-20260110

Correctif

20260113

Publication

15/01/2026

CVE-2025-2874 Moyenne · 4,4
User Submitted Posts – Enable Users to Submit Posts from the Front End

User Submitted Posts <= 20241026 – Authenticated (Admin+) Stored Cross-Site Scripting

The User Submitted Posts – Enable Users to Submit Posts from the Front End plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and including, 20240319 due to insufficient input…

Versions affectées

*-20241026

Correctif

20250327

Publication

02/04/2025

CVE-2024-5002 Moyenne · 4,4
User Submitted Posts – Enable Users to Submit Posts from the Front End

User Submitted Posts – Enable Users to Submit Posts from the Front End <= 20240319 – Authenticated (Admin+) Stored Cross-Site Scripting

The User Submitted Posts – Enable Users to Submit Posts from the Front End plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and including, 20240319 due to insufficient input…

Versions affectées

*-20240319

Correctif

20240516

Publication

22/06/2024

CVE-2023-45603 Critique · 9,8
User Submitted Posts – Enable Users to Submit Posts from the Front End

User Submitted Posts <= 20230902 – Unauthenticated Arbitrary File Upload

The User Submitted Posts plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the usp_attach_images function in versions up to, and including, 20230902. This makes it possible for unauthenticatedattackers to upload…

Versions affectées

*-20230902

Correctif

20230914

Publication

10/10/2023

CVE-2023-7251 Moyenne · 6,4
User Submitted Posts – Enable Users to Submit Posts from the Front End

User Submitted Posts <= 20230901 – Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode

The User Submitted Posts plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's shortcodes in versions up to, and including, 20230901 due to insufficient input sanitization and output escaping. This makes it possible for authenticated…

Versions affectées

*-20230901

Correctif

20230902

Publication

06/09/2023

CVE-2023-4779 Moyenne · 6,4
User Submitted Posts – Enable Users to Submit Posts from the Front End

User Submitted Posts – Enable Users to Submit Posts from the Front End <= 20230811 – Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode

The User Submitted Posts plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's [usp_gallery] shortcode in versions up to, and including, 20230811 due to insufficient input sanitization and output escaping on user supplied attributes like…

Versions affectées

*-20230811

Correctif

20230901

Publication

05/09/2023

CVE-2023-4308 Élevée · 7,2
User Submitted Posts – Enable Users to Submit Posts from the Front End

User Submitted Posts <= 20230809 – Unauthenticated Stored Cross-Site Scripting via 'user-submitted-content'

The User Submitted Posts plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘user-submitted-content’ parameter in versions up to, and including, 20230809 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated…

Versions affectées

*-20230809

Correctif

20230811

Publication

14/08/2023

CVE-2019-25138 Critique · 9,8
User Submitted Posts – Enable Users to Submit Posts from the Front End

User Submitted Posts <= 20190312 – Unauthenticated Arbitrary File Upload

The User Submitted Posts plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the usp_check_images function in versions up to, and including, 20190312. This makes it possible for unauthenticated attackers to…

Versions affectées

[*, 20190426)

Correctif

20190426

Publication

02/05/2019

WP Commander

Rechercher dans toute la base WordPress

Utilisez la recherche globale pour retrouver une extension, un thème, une CVE ou un identifiant de vulnérabilité.

Ouvrir le tableau des vulnérabilités