Input validation vulnerability in User Submitted Posts – Enable Users to Submit Posts from the Front End 20230902

The User Submitted Posts plugin for WordPress may have a vulnerability which allows people to upload files to the affected site’s server without permission. This vulnerability exists in versions up to and including 20230902. It is possible for unauthenticated attackers to upload files with certain extensions, as long as the file does not have the extension ‘php’. This could allow malicious users to execute code on the server, which could cause serious damage.

Detected in:

This information is sourced from www.wpvulnerability.com. An open-source database of vulnerabilities maintained by the community. Help us out by submitting vulnerabilities!

Version compare shows which versions have a vulnerability. For example: >= 2.2.8 <= 2.2.21 means:

> from 2.2.8
= including 2.2.8 & 2.2.21
< to 2.2.21

Is this information incorrect? Please leave us a message.