Vulnerabilities > Plugin Planet > User Submitted Posts

DATE CVE VULNERABILITY TITLE RISK
2023-12-20 CVE-2023-45603 Unrestricted Upload of File with Dangerous Type vulnerability in Plugin-Planet User Submitted Posts
Unrestricted Upload of File with Dangerous Type vulnerability in Jeff Starr User Submitted Posts – Enable Users to Submit Posts from the Front End.This issue affects User Submitted Posts – Enable Users to Submit Posts from the Front End: from n/a through 20230902.
network
low complexity
plugin-planet CWE-434
critical
9.8
2023-09-06 CVE-2023-4779 Unspecified vulnerability in Plugin-Planet User Submitted Posts
The User Submitted Posts plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's [usp_gallery] shortcode in versions up to, and including, 20230811 due to insufficient input sanitization and output escaping on user supplied attributes like 'before'.
network
low complexity
plugin-planet
5.4
2023-08-15 CVE-2023-4308 Unspecified vulnerability in Plugin-Planet User Submitted Posts
The User Submitted Posts plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘user-submitted-content’ parameter in versions up to, and including, 20230809 due to insufficient input sanitization and output escaping.
network
low complexity
plugin-planet
5.4
2023-06-07 CVE-2019-25138 Unrestricted Upload of File with Dangerous Type vulnerability in Plugin-Planet User Submitted Posts
The User Submitted Posts plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the usp_check_images function in versions up to, and including, 20190312.
network
low complexity
plugin-planet CWE-434
critical
9.8
2019-09-20 CVE-2016-11001 Cross-site Scripting vulnerability in Plugin-Planet User Submitted Posts
The user-submitted-posts plugin before 20160215 for WordPress has XSS via the user-submitted-content field.
4.3