← WordPress Vulnerabilities
WordPress security by component

UsersWP – Front-end login form, User Registration, User Profile & Members Directory plugin for WP

UsersWP – Front-end login form, User Registration, User Profile & Members Directory plugin for WP is a WordPress component with 15 published CVE records in this archive. The latest tracked vulnerability was published Jul 09, 2026; the highest CVE/CNA score is 9.8.

Plugin slug: userswp

CVE-2026-13492: UsersWP – Front-end login form, User Registration, User Profile & Members Directory plugin for WP: Arbitrary file deletion

UsersWP – Front-end login form, User Registration, User Profile & Members Directory plugin for WP is affected by arbitrary file deletion. Exploitation requires at least subscriber-level access. A successful request can remove files outside the intended scope and may make the site unavailable. The published affected range is <= 1.2.65.

PublishedJul 09, 2026
Known safe version> 1.2.65
Safe version
Jul 09, 2026 CVE-2026-13492
UsersWP – Front-end login form, User Registration, User Profile & Members Directory plugin for WP: Arbitrary file deletion
UsersWP – Front-end login form, User Registration, User Profile & Members Directory plugin for WP is affected by arbitrary file deletion. Exploitation requires at least subscriber-level access. A successful request can remove files outside the intended scope and may make the site unavailable. The published affected range is <= 1.2.65.
> 1.2.65
CVE8.8
NVDPending
Jun 18, 2026 CVE-2026-12102
UsersWP – Front-end login form, User Registration, User Profile & Members Directory plugin for WP: A security weakness
UsersWP – Front-end login form, User Registration, User Profile & Members Directory plugin for WP is affected by a security weakness. Exploitation requires at least editor-level access. The resulting impact depends on how the affected component exposes the vulnerable operation. The published affected range is <= 1.2.63.
> 1.2.63
CVE2.7
NVDPending
Apr 11, 2026 CVE-2026-4979
UsersWP – Front-end login form, User Registration, User Profile & Members Directory plugin for WP: Server-side request forgery
UsersWP – Front-end login form, User Registration, User Profile & Members Directory plugin for WP is affected by server-side request forgery. Exploitation requires at least subscriber-level access. The vulnerable server can be induced to make attacker-selected network requests. The published affected range is <= 1.2.58.
> 1.2.58
CVE5.0
NVDPending
Apr 10, 2026 CVE-2026-4977
UsersWP – Front-end login form, User Registration, User Profile & Members Directory plugin for WP: A security weakness
UsersWP – Front-end login form, User Registration, User Profile & Members Directory plugin for WP is affected by a security weakness. Exploitation requires at least subscriber-level access. The resulting impact depends on how the affected component exposes the vulnerable operation. The published affected range is <= 1.2.58.
> 1.2.58
CVE4.3
NVDPending
Apr 09, 2026 CVE-2026-5742
UsersWP – Front-end login form, User Registration, User Profile & Members Directory plugin for WP: Cross-site scripting
UsersWP – Front-end login form, User Registration, User Profile & Members Directory plugin for WP is affected by cross-site scripting. Exploitation requires at least subscriber-level access. Injected script can execute in the affected site's origin when the vulnerable output is viewed. The published affected range is <= 1.2.60.
> 1.2.60
CVE6.4
NVDPending
Feb 03, 2026 CVE-2026-25015
UsersWP: Cross-site request forgery
UsersWP is affected by cross-site request forgery. Exposure depends on how the affected operation is made reachable by the site. Exploitation relies on a signed-in privileged user submitting an attacker-controlled request.
See mitigation notes
CVE4.3
NVDPending
Dec 09, 2025 CVE-2025-67593
UsersWP: Cross-site request forgery
UsersWP is affected by cross-site request forgery. Exposure depends on how the affected operation is made reachable by the site. Exploitation relies on a signed-in privileged user submitting an attacker-controlled request.
See mitigation notes
CVE4.3
NVDPending
Nov 21, 2025 CVE-2025-66072
UsersWP: A security weakness
UsersWP is affected by a security weakness. Exposure depends on how the affected operation is made reachable by the site. The resulting impact depends on how the affected component exposes the vulnerable operation.
See mitigation notes
CVE5.3
NVDPending
Nov 01, 2024 CVE-2024-43277
UsersWP: A security weakness
UsersWP is affected by a security weakness. Exposure depends on how the affected operation is made reachable by the site. The resulting impact depends on how the affected component exposes the vulnerable operation.
See mitigation notes
CVE5.3
NVDPending
Aug 03, 2024 CVE-2024-6477
UsersWP: A security weakness
UsersWP is affected by a security weakness. The vulnerable path is reachable without authentication. The resulting impact depends on how the affected component exposes the vulnerable operation.
See mitigation notes
CVE7.5
NVDPending
Jun 29, 2024 CVE-2024-6265
UsersWP – Front-end login form, User Registration, User Profile & Members Directory plugin for: SQL injection
UsersWP – Front-end login form, User Registration, User Profile & Members Directory plugin for is affected by SQL injection. The vulnerable path is reachable without authentication. A successful request can alter database queries and expose or modify WordPress data.
See mitigation notes
CVE9.8
NVDPending
Apr 11, 2024 CVE-2024-31936
UsersWP: Cross-site request forgery
UsersWP is affected by cross-site request forgery. Exposure depends on how the affected operation is made reachable by the site. Exploitation relies on a signed-in privileged user submitting an attacker-controlled request.
See mitigation notes
CVE5.4
NVDPending
Apr 09, 2024 CVE-2024-2423
UsersWP – Front-end login form, User Registration, User Profile & Members Directory plugin for: Cross-site scripting
UsersWP – Front-end login form, User Registration, User Profile & Members Directory plugin for is affected by cross-site scripting. Exploitation requires an authenticated WordPress account. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE6.4
NVDPending
Nov 07, 2023 CVE-2022-47442
UsersWP: A security weakness
UsersWP is affected by a security weakness. Exposure depends on how the affected operation is made reachable by the site. The resulting impact depends on how the affected component exposes the vulnerable operation.
See mitigation notes
CVE5.8
NVD8.8
Mar 07, 2022 CVE-2022-0442
UsersWP: A security weakness
UsersWP is affected by a security weakness. Exposure depends on how the affected operation is made reachable by the site. The resulting impact depends on how the affected component exposes the vulnerable operation.
See mitigation notes
CVE4.3
NVD4.3