/Vulnerability Library

User Submitted Posts <= 20251121 - Unauthenticated Open Redirect

CVE-2025-68509
Verified

Description

The User Submitted Posts plugin for WordPress is vulnerable to Open Redirect in all versions up to and including 20251121. This is due to insufficient validation on the redirect-override POST parameter. Unauthenticated attackers can redirect users to potentially malicious sites by tricking them into submitting a form.

Severity

Medium

Published Date

February 4, 2026

Template Author

shivam kamboj

CVE-2025-68509.yaml
5.0Severity

CVSS Metrics

References

https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/user-submitted-posts/user-submitted-posts-20251121-unauthenticated-open-redirecthttps://plugins.trac.wordpress.org/changeset?old_path=/user-submitted-posts/tags/20251121&new_path=/user-submitted-posts/tags/20251210

Remediation Steps

Update to the latest version.