The User Submitted Posts plugin for WordPress is vulnerable to Open Redirect in all versions up to and including 20251121. This is due to insufficient validation on the redirect-override POST parameter. Unauthenticated attackers can redirect users to potentially malicious sites by tricking them into submitting a form.
id: CVE-2025-68509
info:
name: User Submitted Posts <= 20251121 - Unauthenticated Open Redirect
...