CVE-2026-2126 PUBLISHED

User Submitted Posts <= 20260113 - Incorrect Authorization to Unauthenticated Category Restriction Bypass via 'user-submitted-category' Parameter

Assigner: Wordfence
Reserved: 06.02.2026 Published: 18.02.2026 Updated: 18.02.2026

The User Submitted Posts – Enable Users to Submit Posts from the Front End plugin for WordPress is vulnerable to Incorrect Authorization in all versions up to, and including, 20260113. This is due to the usp_get_submitted_category() function accepting user-submitted category IDs from the POST body without validating them against the admin-configured allowed categories stored in usp_options['categories']. This makes it possible for unauthenticated attackers to assign submitted posts to arbitrary categories, including restricted ones, by crafting a direct POST request with manipulated user-submitted-category[] values, bypassing the frontend category restrictions.

Metrics

CVSS Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
CVSS Score: 5.3

Product Status

Vendor specialk
Product User Submitted Posts – Enable Users to Submit Posts from the Front End
Versions Default: unaffected
  • affected from * to 20260113 (incl.)

Credits

  • M Indra Purnama finder

References

Problem Types

  • CWE-863 Incorrect Authorization CWE