User Submitted Posts <= 20260110 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'usp_access' Shortcode
User Submitted Posts – Enable Users to Submit Posts from the Front End
Minimum safe version
20260217
Update to 20260217 or later to address 17 fixable vulnerabilities
User Submitted Posts <= 20260113 - Incorrect Authorization to Unauthenticated Category Restriction Bypass via 'user-submitted-category' Parameter
User Submitted Posts – Enable Users to Submit Posts from the Front End <= 20251210 - Unauthenticated Stored Cross-Site Scripting via Custom Field
User Submitted Posts <= 20251121 - Unauthenticated Open Redirect
WordPress User Submitted Posts Plugin <= 20241026 is vulnerable to Cross Site Scripting (XSS)
WordPress User Submitted Posts Plugin < 20240516 is vulnerable to Cross Site Scripting (XSS)
CVE-2023-7251
CVE-2023-45603
CVE-2023-41696
CVE-2023-4779
CVE-2023-4308
CVE-2019-25138
User Submitted Posts <= 20190312 - Unauthenticated Arbitrary File Upload
wpscan.com
WordPress User Submitted Posts Plugin <= 20151113 - XSS
WordPress User Submitted Posts plugin <= 20190426 - Arbitrary File Upload vulnerability
CVE-2016-11001