CVEs (6)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
1Plugin Planet 1User Submitted Posts May 13, 2025 Jul 13, 2024 N/A· v4 4.8 MEDIUM· v3 N/A· v2 The User Submitted Posts WordPress plugin before 20240516 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when...Show more |
1Plugin Planet 1User Submitted Posts Apr 28, 2026 Dec 20, 2023 N/A· v4 9.8 CRITICAL· v3 N/A· v2 Unrestricted Upload of File with Dangerous Type vulnerability in Jeff Starr User Submitted Posts – Enable Users to Submit Posts from the Front End.This issue affects User Submitted Posts – Enable Users to Submit Posts fr...Show more |
The User Submitted Posts plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's [usp_gallery] shortcode in versions up to, and including, 20230811 due to insufficient input sanitization and ou...Show more |
1Plugin Planet 1User Submitted Posts Feb 11, 2025 Aug 15, 2023 N/A· v4 5.4 MEDIUM· v3 N/A· v2 The User Submitted Posts plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘user-submitted-content’ parameter in versions up to, and including, 20230809 due to insufficient input sanitization and...Show more |
1Plugin Planet 1User Submitted Posts Apr 8, 2026 Jun 7, 2023 N/A· v4 9.8 CRITICAL· v3 N/A· v2 The User Submitted Posts plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the usp_check_images function in versions up to, and including, 20190312. This makes it possibl...Show more |
1Plugin Planet 1User Submitted Posts Nov 21, 2024 Sep 20, 2019 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 The user-submitted-posts plugin before 20160215 for WordPress has XSS via the user-submitted-content field. |