Description
The User Submitted Posts – Enable Users to Submit Posts from the Front End plugin for WordPress is vulnerable to Incorrect Authorization in all versions up to, and including, 20260113. This is due to the `usp_get_submitted_category()` function accepting user-submitted category IDs from the POST body without validating them against the admin-configured allowed categories stored in `usp_options['categories']`. This makes it possible for unauthenticated attackers to assign submitted posts to arbitrary categories, including restricted ones, by crafting a direct POST request with manipulated `user-submitted-category[]` values, bypassing the frontend category restrictions.
INFO
Published Date :
2026-02-18T09:25:51.296Z
Last Modified :
2026-04-08T16:32:44.750Z
Source :
Wordfence
AFFECTED PRODUCTS
The following products are affected by CVE-2026-2126 vulnerability.
| Vendors | Products |
|---|---|
| Specialk |
|
| Wordpress |
|
REFERENCES
Here, you will find a curated list of external links that provide in-depth information to CVE-2026-2126.