CVE-2025-2874
CVSS 3.1 Score 4.4 of 10 (medium)
Details
Summary
CVE-2025-2874 is a stored Cross-Site Scripting (XSS) vulnerability affecting the User Submitted Posts plugin for WordPress. This issue allows authenticated attackers with administrator-level permissions to inject arbitrary web scripts into admin settings. Consequently, any user accessing an injected page will execute the malicious code. This vulnerability only impacts multi-site installations and installations where unfiltered_html has been disabled. Unchecked input sanitization and output escaping in this plugin are the primary causes of this security weakness.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.