CVE-2025-2874

CVSS 3.1 Score 4.4 of 10 (medium)

Details

Published Apr 3, 2025
Updated: Apr 7, 2025
CWE ID 79

Summary

CVE-2025-2874 is a stored Cross-Site Scripting (XSS) vulnerability affecting the User Submitted Posts plugin for WordPress. This issue allows authenticated attackers with administrator-level permissions to inject arbitrary web scripts into admin settings. Consequently, any user accessing an injected page will execute the malicious code. This vulnerability only impacts multi-site installations and installations where unfiltered_html has been disabled. Unchecked input sanitization and output escaping in this plugin are the primary causes of this security weakness.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share