Back to overview

CVE-2026-11570

MEDIUM Exploitation: PoC
4.2
CVSS 3.1
Description
The User Submitted Posts WordPress plugin before 20260608 does not escape a submitted value before outputting it in an admin-configured display template, leading to a Stored Cross-Site Scripting that can be triggered by unauthenticated users when a non-default display option is enabled.

Metadata

CVE ID
CVE-2026-11570
State
PUBLISHED
Assigner
WPScan
Reserved
2026-06-08 09:20 UTC
Published
2026-07-01 06:00 UTC
Last updated
2026-07-01 10:18 UTC
Vendor / Product
Unknown / User Submitted Posts
Sources
cve.org  ·  NVD

Severity & Metrics

4.2 MEDIUM CVSS 3.1
CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:L/I:L/A:N
SSVC — CISA Coordinator
Exploitation
PoC
Automatable
no
Tech. Impact
partial
Affected products (1)
VendorProductPlatformVersions
Unknown User Submitted Posts 0 < 20260608
Weakness (CWE)
CWESourceDescription
cna CWE-79 Cross-Site Scripting (XSS)
CVSS scores (1)
ScoreSeverityVersionSourceVector
4.2 MEDIUM 3.1 adp CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:L/I:L/A:N
Back to overview