cleantalk
Vulnerabilities and Security Researches

User Submitted Posts – Enable Users to Submit Posts from the Front End, CVE-2024-5002

CVE, Research URL

CVE-2024-5002

Published on
Jul 13, 2024
Research Description
The User Submitted Posts WordPress plugin before 20240516 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)
Affected versions
max 20240516.
Status
vulnerable