Security Advisory

CVE-2026-11570

CVE vulnerability detail - eXtreme Datacenter Security Operations

Published 2026-07-01 06:00:02
Last updated 2026-07-01 10:18:43
Assigner WPScan
CVSS score not scored
State PUBLISHED

Description

The User Submitted Posts WordPress plugin before 20260608 does not escape a submitted value before outputting it in an admin-configured display template, leading to a Stored Cross-Site Scripting that can be triggered by unauthenticated users when a non-default display option is enabled.