
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-2126 is an Incorrect Authorization vulnerability in the User Submitted Posts – Enable Users to Submit Posts from the Front End plugin for WordPress. It affects all versions up to and including 20260113, allowing unauthenticated attackers to assign submitted posts to arbitrary or restricted categories by bypassing frontend category restrictions. The vulnerability was published on February 18, 2026, with a CVSS v3.1 base score of 5.3 (Medium) (Red Hat CVE).
The root cause is classified as CWE-863 (Incorrect Authorization). The vulnerable usp_get_submitted_category() function accepts category IDs directly from the POST request body without validating them against the admin-configured allowed categories stored in usp_options['categories']. An unauthenticated attacker can craft a direct HTTP POST request with manipulated user-submitted-category[] parameter values, bypassing the frontend category restrictions entirely and assigning posts to any category, including those restricted by the site administrator (Red Hat CVE).
Successful exploitation allows unauthenticated attackers to assign user-submitted posts to arbitrary WordPress categories, including those restricted by administrators. The primary impact is on integrity — content can be published or associated with categories in ways not intended by site administrators — while confidentiality and availability are not directly affected. This could be abused to inject content into sensitive or high-visibility categories, potentially enabling spam, misinformation, or SEO manipulation on affected WordPress sites (Red Hat CVE).
No public proof-of-concept exploit code or active in-the-wild exploitation has been reported for CVE-2026-2126. The vulnerability requires no authentication and has low attack complexity, making it trivially exploitable by any remote attacker. The EPSS score is approximately 0.016% (0.000160), indicating a low probability of exploitation in the near term. It does not appear in the CISA Known Exploited Vulnerabilities (KEV) catalog (Red Hat CVE).
curl or Burp Suite, craft a direct HTTP POST request to the form submission endpoint, including manipulated user-submitted-category[] parameter values set to the IDs of restricted or arbitrary categories not exposed in the frontend form.usp_get_submitted_category() function will accept the attacker-supplied category IDs without validating them against usp_options['categories'].user-submitted-category[] values that do not correspond to categories displayed in the frontend form.usp_options['categories']).Site administrators should update the User Submitted Posts plugin to a version released after 20260113 that addresses this authorization flaw. As a temporary workaround, administrators can disable the plugin's frontend post submission functionality until a patched version is available, or manually restrict access to the submission endpoint via server-level controls (e.g., WAF rules blocking manipulation of user-submitted-category[] parameters). Regularly auditing posts assigned to restricted categories can help detect exploitation attempts (Red Hat CVE).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."