Cross-Site Scripting Vulnerability in User Submitted Posts by Jeff Starr
CVE-2026-62084

6.5MEDIUM

Key Information:

Vendor

WordPress

Vendor
CVE Published:
30 September 2026

What is CVE-2026-62084?

A Cross-Site Scripting (XSS) vulnerability has been identified in the User Submitted Posts plugin by Jeff Starr. This flaw allows attackers to inject malicious scripts into web pages, which can then execute in the context of users' browsers. As a result, any data submitted through the plugin could be compromised, leading to potential data leakage or user impersonation. Specifically, this vulnerability affects versions of User Submitted Posts released up until August 10, 2026, necessitating immediate attention and remediation for site administrators to secure their installations.

Affected Version(s)

User Submitted Posts <= 20260810

References

CVSS V3.1

Score:
6.5
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Ananda Dhakal | Patchstack
.