plugin

Userswp Vulnerabilities

39 known security issues reported for the Userswp WordPress plugin. Most recent disclosed Aug 6, 2026.

1 critical 1 high 18 medium 1 low

Running Userswp on your site? Check whether your installed version is affected.

Scan your site free

UsersWP <= 1.2.69 - Authenticated (Subscriber+) Stored Cross-Site Scripting via Badge Widget Variable Substitution

medium

The UsersWP – Front-end login form, User Registration, User Profile & Members Directory plugin for WP plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Badge Widget Variable Substitution in all versions up to, and including, 1.2.69 due to insufficient input sanitization and output escaping. This mak...

CVSS:
6.4
Affected:
up to 1.2.69
Fixed in:
1.2.70
Disclosed:
Aug 6, 2026

CVE-2026-18501 on NVD →

UsersWP <= 1.2.65 - Authenticated (Subscriber+) Arbitrary File Deletion via File Upload Field

high

The UsersWP plugin for WordPress is vulnerable to Arbitrary File Deletion in versions up to, and including, 1.2.65. This is due to insufficient validation of file-field values in the UsersWP_Validation::validate_fields() function (which falls through to sanitize_text_field() for fields of type 'file', leaving directory...

CVSS:
8.8
Affected:
up to 1.2.65
Fixed in:
1.2.66
Disclosed:
Jul 9, 2026

CVE-2026-13492 on NVD →

UsersWP – Front-end login form, User Registration, User Profile & Members Directory plugin for WP < 1.2.67 - Two-Factor Authentication Bypass

medium

The UsersWP – Front-end login form, User Registration, User Profile & Members Directory plugin for WP plugin for WordPress is vulnerable to Two-Factor Authentication Bypass in all versions up to 1.2.67 (exclusive). This makes it possible for unauthenticated attackers to bypass the second factor of authentication.

CVSS:
5.3
Affected:
up to 1.2.67
Fixed in:
1.2.67
Disclosed:
Jul 8, 2026

CVE-2026-13690 on NVD →

UsersWP <= 1.2.63 - Insecure Direct Object Reference to Authenticated (Editor+) Arbitrary User Avatar/Banner Reset via 'user_id' Parameter

low

The UsersWP – Front-end login form, User Registration, User Profile & Members Directory plugin for WP plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 1.2.63 via the 'user_id' parameter due to missing validation on a user controlled key. This makes it possible...

CVSS:
2.7
Affected:
up to 1.2.63
Fixed in:
1.2.64
Disclosed:
Jun 17, 2026

CVE-2026-12102 on NVD →

UsersWP <= 1.2.58 - Authenticated (Subscriber+) Server-Side Request Forgery via 'uwp_crop' Parameter

medium

The UsersWP – Front-end login form, User Registration, User Profile & Members Directory plugin for WP plugin for WordPress is vulnerable to blind Server-Side Request Forgery in all versions up to, and including, 1.2.58. This is due to insufficient URL origin validation in the process_image_crop() method when processing...

CVSS:
5
Affected:
up to 1.2.58
Fixed in:
1.2.59
Disclosed:
Apr 10, 2026

CVE-2026-4979 on NVD →

UsersWP <= 1.2.58 - Authenticated (Subscriber+) Restricted Usermeta Modification via 'htmlvar' Parameter

medium

The UsersWP – Front-end login form, User Registration, User Profile & Members Directory plugin for WordPress is vulnerable to Improper Access Control in all versions up to, and including, 1.2.58 This is due to insufficient field-level permission validation in the upload_file_remove() AJAX handler where the $htmlvar par...

CVSS:
4.3
Affected:
up to 1.2.58
Fixed in:
1.2.59
Disclosed:
Apr 9, 2026

CVE-2026-4977 on NVD →

UsersWP <= 1.2.60 - Authenticated (Subscriber+) Stored Cross-Site Scripting via User Badge Link Substitution

medium

The UsersWP plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to and including 1.2.60. This is due to insufficient input sanitization of user-supplied URL fields and improper output escaping when rendering user profile data in badge widgets. This makes it possible for authenticated attack...

CVSS:
6.4
Affected:
up to 1.2.60
Fixed in:
1.2.61
Disclosed:
Apr 8, 2026

CVE-2026-5742 on NVD →

UsersWP &#8211; Front-end login form, User Registration, User Profile &amp; Members Directory plugin for WP [userswp] <= 1.2.53 (unfixed)

unknown

[en] Cross-Site Request Forgery (CSRF) vulnerability in Stiofan UsersWP userswp allows Cross Site Request Forgery.This issue affects UsersWP: from n/a through <= 1.2.53.

Affected:
up to 1.2.53
Fix:
No patched version reported
Disclosed:
Feb 3, 2026

CVE-2026-25015 on NVD →

UsersWP <= 1.2.53 - Cross-Site Request Forgery

medium

The UsersWP – Front-end login form, User Registration, User Profile & Members Directory plugin for WP plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.2.53. This is due to missing or incorrect nonce validation on the ajax_avatar_banner_upload() function. This make...

CVSS:
4.3
Affected:
up to 1.2.53
Fixed in:
1.2.54
Disclosed:
Jan 28, 2026

CVE-2026-25015 on NVD →

UsersWP <= 1.2.48 - Cross-Site Request Forgery

medium

The UsersWP – Front-end login form, User Registration, User Profile & Members Directory plugin for WP plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.2.48. This is due to missing or incorrect nonce validation on a function. This makes it possible for unauthentica...

CVSS:
4.3
Affected:
up to 1.2.48
Fixed in:
1.2.49
Disclosed:
Dec 15, 2025

CVE-2025-67593 on NVD →

UsersWP &#8211; Front-end login form, User Registration, User Profile &amp; Members Directory plugin for WP [userswp] <= 1.2.48 (unfixed)

unknown

[en] Cross-Site Request Forgery (CSRF) vulnerability in Stiofan UsersWP userswp allows Cross Site Request Forgery.This issue affects UsersWP: from n/a through <= 1.2.48.

Affected:
up to 1.2.48
Fix:
No patched version reported
Disclosed:
Dec 9, 2025

CVE-2025-67593 on NVD →

UsersWP <= 1.2.47 - Missing Authorization

medium

The UsersWP – Front-end login form, User Registration, User Profile & Members Directory plugin for WP plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in all versions up to, and including, 1.2.47. This makes it possible for unauthenticated attackers to perform an...

CVSS:
5.3
Affected:
up to 1.2.47
Fixed in:
1.2.48
Disclosed:
Nov 25, 2025

CVE-2025-66072 on NVD →

UsersWP &#8211; Front-end login form, User Registration, User Profile &amp; Members Directory plugin for WP [userswp] <= 1.2.47 (unfixed)

unknown

[en] Missing Authorization vulnerability in Stiofan UsersWP userswp allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects UsersWP: from n/a through <= 1.2.47.

Affected:
up to 1.2.47
Fix:
No patched version reported
Disclosed:
Nov 21, 2025

CVE-2025-66072 on NVD →

UsersWP &#8211; Front-end login form, User Registration, User Profile &amp; Members Directory plugin for WP [userswp] < 1.2.45

unknown

[en] The UsersWP – Front-end login form, User Registration, User Profile & Members Directory plugin for WordPress plugin for WordPress is vulnerable to time-based SQL Injection via the ‘upload_file_remove’ function and 'htmlvar' parameter in all versions up to, and including, 1.2.44 due to insufficient escaping on the...

Affected:
up to 1.2.45
Fixed in:
1.2.45
Disclosed:
Sep 6, 2025

CVE-2025-10003 on NVD →

UsersWP – Front-end login form, User Registration, User Profile & Members Directory plugin for WP <= 1.2.44 - Authenticated (Subscriber+) SQL Injection

medium

The UsersWP – Front-end login form, User Registration, User Profile & Members Directory plugin for WordPress plugin for WordPress is vulnerable to time-based SQL Injection via the ‘upload_file_remove’ function and 'htmlvar' parameter in all versions up to, and including, 1.2.44 due to insufficient escaping on the user...

CVSS:
6.5
Affected:
up to 1.2.44
Fixed in:
1.2.45
Disclosed:
Sep 5, 2025

CVE-2025-10003 on NVD →

UsersWP <= 1.2.42 - Authenticated (Contributor+) Stored Cross-Site Scripting

medium

The UsersWP – Front-end login form, User Registration, User Profile & Members Directory plugin for WP plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'uwp_profile' and 'uwp_profile_header' shortcodes in all versions up to, and including, 1.2.42 due to insufficient input sanitization a...

CVSS:
6.4
Affected:
up to 1.2.42
Fixed in:
1.2.43
Disclosed:
Aug 27, 2025

CVE-2025-9344 on NVD →

UsersWP &#8211; Front-end login form, User Registration, User Profile &amp; Members Directory plugin for WP [userswp] < 1.2.16

unknown

[en] Missing Authorization vulnerability in AyeCode Ltd UsersWP allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects UsersWP: from n/a through 1.2.15.

Affected:
up to 1.2.16
Fixed in:
1.2.16
Disclosed:
Nov 1, 2024

CVE-2024-43277 on NVD →

UsersWP <= 1.2.15 - Missing Authorization

medium

The UsersWP plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the activation_redirect() function in versions up to, and including, 1.2.15. This makes it possible for unauthenticated attackers to trigger the activation redirect.

CVSS:
5.3
Affected:
up to 1.2.15
Fixed in:
1.2.16
Disclosed:
Aug 16, 2024

CVE-2024-43277 on NVD →

UsersWP &#8211; Front-end login form, User Registration, User Profile &amp; Members Directory plugin for WP [userswp] < 1.2.12

unknown

[en] The UsersWP WordPress plugin before 1.2.12 uses predictable filenames when an admin generates an export, which could allow unauthenticated attackers to download them and retrieve sensitive information such as IP, username, and email address

Affected:
up to 1.2.12
Fixed in:
1.2.12
Disclosed:
Aug 3, 2024

CVE-2024-6477 on NVD →

UsersWP – Front-end login form, User Registration, User Profile & Members Directory plugin for WP <= 1.2.11 - Unauthenticated Information Disclosure via Unprotected Directories

medium

The UsersWP – Front-end login form, User Registration, User Profile & Members Directory plugin for WP plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 1.2.11due to insufficient protections on the '/uploads/cache/' directory. This makes it possible for unauthenti...

CVSS:
5.3
Affected:
up to 1.2.11
Fixed in:
1.2.12
Disclosed:
Jul 13, 2024

CVE-2024-6477 on NVD →

UsersWP &#8211; Front-end login form, User Registration, User Profile &amp; Members Directory plugin for WP [userswp] < 1.2.11

unknown

[en] The UsersWP – Front-end login form, User Registration, User Profile & Members Directory plugin for WordPress plugin for WordPress is vulnerable to time-based SQL Injection via the ‘uwp_sort_by’ parameter in all versions up to, and including, 1.2.10 due to insufficient escaping on the user supplied parameter and la...

Affected:
up to 1.2.11
Fixed in:
1.2.11
Disclosed:
Jun 29, 2024

CVE-2024-6265 on NVD →

UsersWP – Front-end login form, User Registration, User Profile & Members Directory plugin for WordPress <= 1.2.10 - Unauthenticated SQL Injection via 'uwp_sort_by'

critical

The UsersWP – Front-end login form, User Registration, User Profile & Members Directory plugin for WordPress plugin for WordPress is vulnerable to time-based SQL Injection via the ‘uwp_sort_by’ parameter in all versions up to, and including, 1.2.10 due to insufficient escaping on the user supplied parameter and lack of...

CVSS:
9.8
Affected:
up to 1.2.10
Fixed in:
1.2.11
Disclosed:
Jun 28, 2024

CVE-2024-6265 on NVD →

UsersWP &#8211; Front-end login form, User Registration, User Profile &amp; Members Directory plugin for WP [userswp] < 1.2.6

unknown

[en] Cross-Site Request Forgery (CSRF) vulnerability in AyeCode Ltd UsersWP.This issue affects UsersWP: from n/a before 1.2.6.

Affected:
up to 1.2.6
Fixed in:
1.2.6
Disclosed:
Apr 11, 2024

CVE-2024-31936 on NVD →

UsersWP <= 1.2.4 - Cross-Site Request Forgery

medium

The UsersWP – Front-end login form, User Registration, User Profile & Members Directory plugin for WordPress plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.2.4. This is due to missing or incorrect nonce validation on an unknown function. This makes it possible f...

CVSS:
4.3
Affected:
up to 1.2.4
Fixed in:
1.2.6
Disclosed:
Apr 10, 2024

CVE-2024-31936 on NVD →

UsersWP &#8211; Front-end login form, User Registration, User Profile &amp; Members Directory plugin for WP [userswp] < 1.2.7

unknown

[en] The UsersWP – Front-end login form, User Registration, User Profile & Members Directory plugin for WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's shortcode(s) in all versions up to, and including, 1.2.6 due to insufficient input sanitization and output escaping on user...

Affected:
up to 1.2.7
Fixed in:
1.2.7
Disclosed:
Apr 9, 2024

CVE-2024-2423 on NVD →

UsersWP <= 1.2.6 - Authenticated(Contributor+) Stored Cross-Site Scripting via Shortcode

medium

The UsersWP – Front-end login form, User Registration, User Profile & Members Directory plugin for WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's shortcode(s) in all versions up to, and including, 1.2.6 due to insufficient input sanitization and output escaping on user supp...

CVSS:
6.4
Affected:
up to 1.2.6
Fixed in:
1.2.7
Disclosed:
Mar 14, 2024

CVE-2024-2423 on NVD →

UsersWP &#8211; Front-end login form, User Registration, User Profile &amp; Members Directory plugin for WP [userswp] < 1.2.3.10

unknown

[en] Improper Neutralization of Formula Elements in a CSV File vulnerability in AyeCode Ltd UsersWP.This issue affects UsersWP: from n/a through 1.2.3.9.

Affected:
up to 1.2.3.10
Fixed in:
1.2.3.10
Disclosed:
Nov 7, 2023

CVE-2022-47442 on NVD →

UsersWP <= 1.2.3.22 - Cross-Site Request Forgery

medium

The UsersWP – Front-end login form, User Registration, User Profile & Members Directory plugin for WordPress plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to 1.2.3.23 (exclusive). This is due to missing or incorrect nonce validation on the ajax_profile_image_remove function. This...

CVSS:
4.3
Affected:
up to 1.2.3.23
Fixed in:
1.2.3.23
Disclosed:
Nov 1, 2023

UsersWP &#8211; Front-end login form, User Registration, User Profile &amp; Members Directory plugin for WP [userswp] < 1.2.3.23

unknown

The UsersWP – Front-end login form, User Registration, User Profile & Members Directory plugin for WordPress plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to 1.2.3.23 (exclusive). This is due to missing or incorrect nonce validation on the ajax_profile_image_remove function. This...

Affected:
up to 1.2.3.23
Fixed in:
1.2.3.23
Disclosed:
Nov 1, 2023

UsersWP &#8211; Front-end login form, User Registration, User Profile &amp; Members Directory plugin for WP [userswp] < 1.2.3.10

unknown

Update the WordPress UsersWP – Front-end login form, User Registration, User Profile & Members Directory plugin for WordPress plugin to the latest available version (at least 1.2.3.10). WordfenceTeam discovered and reported this CSV Injection vulnerability in WordPress UsersWP – Front-end login form, User Registration,...

Affected:
up to 1.2.3.10
Fixed in:
1.2.3.10
Disclosed:
Dec 23, 2022

UsersWP <= 1.2.3.9 - Authenticated (Administrator+) CSV Injection

medium

The UsersWP plugin for WordPress is vulnerable to CSV Injection in versions up to, and including, 1.2.3.9 via the process_users_export function. This allows administrator-level attackers to embed untrusted input into exported CSV files, which can result in code execution when these files are downloaded and opened on a...

CVSS:
5.5
Affected:
up to 1.2.3.9
Fixed in:
1.2.3.10
Disclosed:
Dec 21, 2022

CVE-2022-47442 on NVD →

UsersWP &#8211; Front-end login form, User Registration, User Profile &amp; Members Directory plugin for WP [userswp] < 1.2.3.10

unknown

The UsersWP plugin for WordPress is vulnerable to CSV Injection in versions up to, and including, 1.2.3.9 via the process_users_export function. This allows administrator-level attackers to embed untrusted input into exported CSV files, which can result in code execution when these files are downloaded and opened on a...

Affected:
up to 1.2.3.10
Fixed in:
1.2.3.10
Disclosed:
Dec 21, 2022

UsersWP &#8211; Front-end login form, User Registration, User Profile &amp; Members Directory plugin for WP [userswp] < 1.2.3.1

unknown

[en] The UsersWP WordPress plugin before 1.2.3.1 is missing access controls when updating a user avatar, and does not make sure file names for user avatars are unique, allowing a logged in user to overwrite another users avatar.

Affected:
up to 1.2.3.1
Fixed in:
1.2.3.1
Disclosed:
Mar 7, 2022

CVE-2022-0442 on NVD →

UsersWP <= 1.2.3 - Subscriber+ User Avatar Override

medium

The UsersWP WordPress plugin before 1.2.3.1 is missing access controls when updating a user avatar, and does not make sure file names for user avatars are unique, allowing a logged in user to overwrite another users avatar.

CVSS:
4.3
Affected:
up to 1.2.3.1
Fixed in:
1.2.3.1
Disclosed:
Feb 14, 2022

CVE-2022-0442 on NVD →

UsersWP – User Registration & User Profile <= 1.2.2.28 - Reflected Cross-Site Scripting

medium

The UsersWP – User Registration & User Profile plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via several parameters in versions up to, and including, 1.2.2.28 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web s...

CVSS:
6.1
Affected:
up to 1.2.2.28
Fixed in:
1.2.2.29
Disclosed:
Sep 6, 2021

UsersWP &#8211; Front-end login form, User Registration, User Profile &amp; Members Directory plugin for WP [userswp] < 1.2.2.29

unknown

The UsersWP – User Registration & User Profile plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via several parameters in versions up to, and including, 1.2.2.28 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web s...

Affected:
up to 1.2.2.29
Fixed in:
1.2.2.29
Disclosed:
Sep 6, 2021

UsersWP &#8211; Front-end login form, User Registration, User Profile &amp; Members Directory plugin for WP [userswp] < 1.2.43

unknown
Affected:
up to 1.2.43
Fixed in:
1.2.43

CVE-2025-9344 on NVD →

UsersWP &#8211; Front-end login form, User Registration, User Profile &amp; Members Directory plugin for WP [userswp] < 1.2.3.23

unknown

The plugin does not have CSRF check when deleting profile pictures, which could allow attackers to make logged in users perform unwanted actions via a CSRF attack

Affected:
up to 1.2.3.23
Fixed in:
1.2.3.23

UsersWP &#8211; Front-end login form, User Registration, User Profile &amp; Members Directory plugin for WP [userswp] < 1.2.2.29

unknown
Affected:
up to 1.2.2.29
Fixed in:
1.2.2.29

Protect your WordPress site

Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.

Scan your site free

← Back to the vulnerability database