← WordPress Vulnerabilities
WordPress security by component

UsersWP – Front-end login form, User Registration, User Profile & Members Directory plugin for WP

UsersWP provides front-end user registration, login, profiles, account pages, and member directory features for WordPress.

UsersWP – Front-end login form, User Registration, User Profile & Members Directory plugin for WP (userswp) is a WordPress plugin with 17 published CVE records in this archive. The latest tracked vulnerability was published Sep 11, 2026; the highest published CVSS base score is 9.8.

Plugin slug: userswp

CVE-2026-19991: UsersWP – Front-end login form, User Registration, User Profile & Members Directory plugin for WP: Arbitrary file deletion

UsersWP – Front-end login form, User Registration, User Profile & Members Directory plugin for WP is affected by arbitrary file deletion. Exploitation requires an authenticated subscriber account. A successful request can remove files outside the intended scope and may make the site unavailable. The published affected range is <= 1.2.70.

PublishedSep 11, 2026
Safe version guidanceSee mitigation notes
Published vulnerabilities for userswp
Safe version
Sep 11, 2026 CVE-2026-19991
UsersWP – Front-end login form, User Registration, User Profile & Members Directory plugin for WP: Arbitrary file deletion
UsersWP – Front-end login form, User Registration, User Profile & Members Directory plugin for WP is affected by arbitrary file deletion. Exploitation requires an authenticated subscriber account. A successful request can remove files outside the intended scope and may make the site unavailable. The published affected range is <= 1.2.70.
See mitigation notes
CVE8.1
NVDPending
Jul 29, 2026 CVE-2026-13690
UsersWP provider selection permits two-factor authentication bypass
UsersWP before 1.2.67 lets an attacker who already knows a protected user's username and password bypass that user's second factor. After the password stage supplies a user-specific uwp-auth-id and wp-auth-nonce, the unauthenticated admin-ajax action uwp_ajax_login_process_2fa reaches Forms::process_login_2fa(). The handler accepts the attacker-controlled provider parameter but, before 1.2.67, validates a second factor only when its value exactly matches totp, email or backup_codes. Any other provider value skips every validation branch, after which the handler deletes the login nonce, calls wp_set_auth_cookie() for the selected user and reports successful authentication. The linked WPScan advisory withholds its request proof of concept until August 8, 2026, but the official 1.2.66/1.2.67 source diff discloses this data path.
1.2.67
CVE7.4
NVDPending
Jul 09, 2026 CVE-2026-13492
UsersWP – Front-end login form, User Registration, User Profile & Members Directory plugin for WP: Arbitrary file deletion
UsersWP – Front-end login form, User Registration, User Profile & Members Directory plugin for WP is affected by arbitrary file deletion. Exploitation requires an authenticated subscriber account. A successful request can remove files outside the intended scope and may make the site unavailable. The published affected range is <= 1.2.65.
See mitigation notes
CVE8.8
NVDPending
Jun 18, 2026 CVE-2026-12102
UsersWP – Front-end login form, User Registration, User Profile & Members Directory plugin for WP: Broken access control
UsersWP – Front-end login form, User Registration, User Profile & Members Directory plugin for WP is affected by broken access control. Exploitation requires an authenticated editor account. A successful request can reach data or an operation that should be restricted to another user or a more privileged role. The published affected range is <= 1.2.63.
See mitigation notes
CVE2.7
NVDPending
Apr 11, 2026 CVE-2026-4979
UsersWP – Front-end login form, User Registration, User Profile & Members Directory plugin for WP: Server-side request forgery
UsersWP – Front-end login form, User Registration, User Profile & Members Directory plugin for WP is affected by server-side request forgery. Exploitation requires an authenticated subscriber account. The vulnerable server can be induced to make attacker-selected network requests. The published affected range is <= 1.2.58.
See mitigation notes
CVE5.0
NVDPending
Apr 10, 2026 CVE-2026-4977
UsersWP – Front-end login form, User Registration, User Profile & Members Directory plugin for WP: A security weakness
UsersWP – Front-end login form, User Registration, User Profile & Members Directory plugin for WP is affected by a security weakness. Exploitation requires an authenticated subscriber account. The resulting impact depends on how the affected component exposes the vulnerable operation. The published affected range is <= 1.2.58.
See mitigation notes
CVE4.3
NVDPending
Apr 09, 2026 CVE-2026-5742
UsersWP – Front-end login form, User Registration, User Profile & Members Directory plugin for WP: Cross-site scripting
UsersWP – Front-end login form, User Registration, User Profile & Members Directory plugin for WP is affected by cross-site scripting. Exploitation requires an authenticated subscriber account. Injected script can execute in the affected site's origin when the vulnerable output is viewed. The published affected range is <= 1.2.60.
See mitigation notes
CVE6.4
NVDPending
Feb 03, 2026 CVE-2026-25015
UsersWP: Cross-site request forgery
UsersWP is affected by cross-site request forgery. Exposure depends on how the affected operation is made reachable by the site. Exploitation relies on a signed-in privileged user submitting an attacker-controlled request.
See mitigation notes
CVE4.3
NVDPending
Dec 09, 2025 CVE-2025-67593
UsersWP: Cross-site request forgery
UsersWP is affected by cross-site request forgery. Exposure depends on how the affected operation is made reachable by the site. Exploitation relies on a signed-in privileged user submitting an attacker-controlled request.
See mitigation notes
CVE4.3
NVDPending
Nov 21, 2025 CVE-2025-66072
UsersWP: A security weakness
UsersWP is affected by a security weakness. Exposure depends on how the affected operation is made reachable by the site. The resulting impact depends on how the affected component exposes the vulnerable operation.
See mitigation notes
CVE5.3
NVDPending
Nov 01, 2024 CVE-2024-43277
UsersWP: A security weakness
UsersWP is affected by a security weakness. Exposure depends on how the affected operation is made reachable by the site. The resulting impact depends on how the affected component exposes the vulnerable operation.
See mitigation notes
CVE5.3
NVDPending
Aug 03, 2024 CVE-2024-6477
UsersWP: A security weakness
UsersWP is affected by a security weakness. The vulnerable path is reachable without authentication. The resulting impact depends on how the affected component exposes the vulnerable operation.
See mitigation notes
CVE7.5
NVDPending
Jun 29, 2024 CVE-2024-6265
UsersWP – Front-end login form, User Registration, User Profile & Members Directory plugin for: SQL injection
UsersWP – Front-end login form, User Registration, User Profile & Members Directory plugin for is affected by SQL injection. The vulnerable path is reachable without authentication. A successful request can alter database queries and expose or modify WordPress data.
See mitigation notes
CVE9.8
NVDPending
Apr 11, 2024 CVE-2024-31936
UsersWP: Cross-site request forgery
UsersWP is affected by cross-site request forgery. Exposure depends on how the affected operation is made reachable by the site. Exploitation relies on a signed-in privileged user submitting an attacker-controlled request.
See mitigation notes
CVE5.4
NVDPending
Apr 09, 2024 CVE-2024-2423
UsersWP – Front-end login form, User Registration, User Profile & Members Directory plugin for: Cross-site scripting
UsersWP – Front-end login form, User Registration, User Profile & Members Directory plugin for is affected by cross-site scripting. Exploitation requires an authenticated contributor account. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE6.4
NVDPending
Nov 07, 2023 CVE-2022-47442
UsersWP: A security weakness
UsersWP is affected by a security weakness. Exposure depends on how the affected operation is made reachable by the site. The resulting impact depends on how the affected component exposes the vulnerable operation.
See mitigation notes
CVE5.8
NVD8.8
Mar 07, 2022 CVE-2022-0442
UsersWP: A security weakness
UsersWP is affected by a security weakness. Exposure depends on how the affected operation is made reachable by the site. The resulting impact depends on how the affected component exposes the vulnerable operation.
See mitigation notes
CVEPending
NVD4.3