CVE-2026-11570: CWE-79 Cross-Site Scripting (XSS) in User Submitted Posts
The User Submitted Posts WordPress plugin before 20260608 does not escape a submitted value before outputting it in an admin-configured display template, leading to a Stored Cross-Site Scripting that can be triggered by unauthenticated users when a non-default display option is enabled.
AI Analysis
Technical Summary
CVE-2026-11570 describes a stored XSS vulnerability in the User Submitted Posts WordPress plugin prior to version 20260608. The plugin fails to escape user-submitted input before rendering it in an admin-configured display template. This flaw allows unauthenticated attackers to inject malicious scripts that execute in the context of the admin interface, but only when a non-default display option is enabled. The vulnerability has a CVSS 3.1 base score of 4.2, reflecting a medium severity with network attack vector, high attack complexity, no privileges required, and requiring user interaction. No official patch or remediation level is currently documented, and no known exploits are reported in the wild.
Potential Impact
Successful exploitation could allow an attacker to execute arbitrary scripts in the context of the WordPress admin interface, potentially leading to limited confidentiality and integrity impacts. The vulnerability does not affect availability. Because the attack requires user interaction and a specific display configuration, the risk is somewhat constrained.
Mitigation Recommendations
Patch status is not yet confirmed — check the vendor advisory for current remediation guidance. Until an official fix is available, administrators should avoid enabling non-default display options that render user-submitted content or apply manual input sanitization and escaping in display templates to mitigate the risk.
CVE-2026-11570: CWE-79 Cross-Site Scripting (XSS) in User Submitted Posts
Description
The User Submitted Posts WordPress plugin before 20260608 does not escape a submitted value before outputting it in an admin-configured display template, leading to a Stored Cross-Site Scripting that can be triggered by unauthenticated users when a non-default display option is enabled.
CVSS v3.1
Score 4.2medium
Weaknesses
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
CVE-2026-11570 describes a stored XSS vulnerability in the User Submitted Posts WordPress plugin prior to version 20260608. The plugin fails to escape user-submitted input before rendering it in an admin-configured display template. This flaw allows unauthenticated attackers to inject malicious scripts that execute in the context of the admin interface, but only when a non-default display option is enabled. The vulnerability has a CVSS 3.1 base score of 4.2, reflecting a medium severity with network attack vector, high attack complexity, no privileges required, and requiring user interaction. No official patch or remediation level is currently documented, and no known exploits are reported in the wild.
Potential Impact
Successful exploitation could allow an attacker to execute arbitrary scripts in the context of the WordPress admin interface, potentially leading to limited confidentiality and integrity impacts. The vulnerability does not affect availability. Because the attack requires user interaction and a specific display configuration, the risk is somewhat constrained.
Mitigation Recommendations
Patch status is not yet confirmed — check the vendor advisory for current remediation guidance. Until an official fix is available, administrators should avoid enabling non-default display options that render user-submitted content or apply manual input sanitization and escaping in display templates to mitigate the risk.
Technical Details
- Data Version
- 5.2
- Assigner Short Name
- WPScan
- Date Reserved
- 2026-06-08T09:20:15.246Z
- Cvss Version
- 3.1
- State
- PUBLISHED
- Remediation Level
- null
Threat ID: 6a44f13827e9c797195bba67
Added to database: 07/01/2026, 10:51:36 UTC
Last enriched: 07/08/2026, 13:06:58 UTC
Last updated: 08/14/2026, 12:49:48 UTC
Views: 83
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
External Links
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.