Live Vulnerability Intelligence
Threat Database
Search CVEs, inspect descriptions, and open detail pages with AI-assisted technical context.
Threat Entry
Updated 2026-07-01
CVE-2026-11570 - Before 20260608 Does Not Escape A Submitted Value Plugin
The User Submitted Posts WordPress plugin before 20260608 does not escape a submitted value before outputting it in an admin-configured display template, leading to a Stored Cross-Site Scripting that can be triggered by unauthenticated users when a non-default display option is enabled.
PLUGIN
Before 20260608 Does Not Escape A Submitted Value
CVE-2026-11570
Risk Score
