Cross-Site Scripting
8 records66.7%First: 2016. Latest: 2026.
Plugin security history
The Wordfence Intelligence dataset currently contains 12 vulnerability records associated with User Submitted Posts – Enable Users to Submit Posts from the Front End, published between 2016 and 2026.
Dataset last synchronized: 2026-08-02 09:41:47 UTC
At a glance
| Year | Records | Relative volume |
|---|---|---|
| 2016 | 1 | |
| 2019 | 1 | |
| 2023 | 4 | |
| 2024 | 1 | |
| 2025 | 1 | |
| 2026 | 4 |
| Severity | Records | Share |
|---|---|---|
| Critical | 2 | 16.7% |
| High | 3 | 25% |
| Medium | 7 | 58.3% |
First: 2016. Latest: 2026.
First: 2019. Latest: 2023.
First: 2026. Latest: 2026.
First: 2026. Latest: 2026.
Patch status reflects the latest successfully synchronized source dataset and must be checked against the installed version.
202602172026011020260113202512102025032720240516202309142023090220230901202308112019042620160215Ranges are deduplicated by source range record and shown with the associated disclosure and known patched versions.
| Affected range | Vulnerability | Published | Patched version | Severity |
|---|---|---|---|---|
*-20260113 | User Submitted Posts <= 20260113 - Incorrect Authorization to Unauthenticated Category Restriction Bypass via 'user-submitted-category' Parameter | February 17, 2026 | 20260217 | Medium |
*-20251210 | User Submitted Posts – Enable Users to Submit Posts from the Front End <= 20251210 - Unauthenticated Stored Cross-Site Scripting via Custom Field | January 23, 2026 | 20260110 | High |
*-20260110 | User Submitted Posts <= 20260110 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'usp_access' Shortcode | January 15, 2026 | 20260113 | Medium |
*-20251121 | User Submitted Posts <= 20251121 - Unauthenticated Open Redirect | January 1, 2026 | 20251210 | Medium |
*-20241026 | User Submitted Posts <= 20241026 - Authenticated (Admin+) Stored Cross-Site Scripting | April 2, 2025 | 20250327 | Medium |
*-20240319 | User Submitted Posts – Enable Users to Submit Posts from the Front End <= 20240319 - Authenticated (Admin+) Stored Cross-Site Scripting | June 22, 2024 | 20240516 | Medium |
*-20230902 | User Submitted Posts <= 20230902 - Unauthenticated Arbitrary File Upload | October 10, 2023 | 20230914 | Critical |
*-20230901 | User Submitted Posts <= 20230901 - Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode | September 6, 2023 | 20230902 | Medium |
*-20230811 | User Submitted Posts – Enable Users to Submit Posts from the Front End <= 20230811 - Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode | September 5, 2023 | 20230901 | Medium |
*-20230809 | User Submitted Posts <= 20230809 - Unauthenticated Stored Cross-Site Scripting via 'user-submitted-content' | August 14, 2023 | 20230811 | High |
[*, 20190426) | User Submitted Posts <= 20190312 - Unauthenticated Arbitrary File Upload | May 2, 2019 | 20190426 | Critical |
[*, 20160215) | User Submitted Posts < 20160215 - Reflected Cross-Site Scripting | February 10, 2016 | 20160215 | High |
Selected source records
Published: February 17, 2026
Published: January 23, 2026
Published: January 15, 2026
Published: January 1, 2026
Published: April 2, 2025
Published: June 22, 2024
Published: October 10, 2023
Published: September 6, 2023
Published: May 2, 2019
Published: October 10, 2023
Published: January 23, 2026
Published: August 14, 2023
Published: February 10, 2016
Published: January 15, 2026
Published: September 6, 2023
Published: September 5, 2023
Running an affected version does not prove that a website was compromised. Suspicious redirects, unknown administrators, injected content, unexpected files or recurring malware may require a manual investigation.
Vulnerability data: Wordfence Intelligence. Analysis and practical guidance: 3Zero Digital.
This page aggregates active Production Feed records. Counts are not software-quality rankings, and an affected version does not prove exploitation or infection. Read the full methodology.