Vulnerabilities and security researches foruserswp userswp
Direction: descendingFeb 27, 2026
UsersWP – Front-end login form, User Registration, User Profile & Members Directory plugin for WordPress # CVE-2026-25015
- CVE, Research URL
- Date
- Feb 03, 2026
- Research Description
- Cross-Site Request Forgery (CSRF) vulnerability in Stiofan UsersWP userswp allows Cross Site Request Forgery.This issue affects UsersWP: from n/a through <= 1.2.53.
- Affected versions
-
max 1.2.53.
- Status
-
vulnerable
Dec 11, 2025
UsersWP – Front-end login form, User Registration, User Profile & Members Directory plugin for WordPress # CVE-2025-66072
- CVE, Research URL
- Date
- Nov 21, 2025
- Research Description
- Missing Authorization vulnerability in Stiofan UsersWP userswp allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects UsersWP: from n/a through <= 1.2.47.
- Affected versions
-
max 1.2.47.
- Status
-
vulnerable
Sep 07, 2025
UsersWP – Front-end login form, User Registration, User Profile & Members Directory plugin for WordPress # CVE-2025-10003
- CVE, Research URL
- Date
- Sep 06, 2025
- Research Description
- The UsersWP – Front-end login form, User Registration, User Profile & Members Directory plugin for WordPress plugin for WordPress is vulnerable to time-based SQL Injection via the ‘upload_file_remove’ function and 'htmlvar' parameter in all versions up to, and including, 1.2.44 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for unauthenticated attackers to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database.
- Affected versions
-
max 1.2.45.
- Status
-
vulnerable
Aug 28, 2025
UsersWP – Front-end login form, User Registration, User Profile & Members Directory plugin for WordPress # CVE-2025-9344
- CVE, Research URL
- Date
- Aug 28, 2025
- Research Description
- The UsersWP – Front-end login form, User Registration, User Profile & Members Directory plugin for WP plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'uwp_profile' and 'uwp_profile_header' shortcodes in all versions up to, and including, 1.2.42 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.
- Affected versions
-
max 1.2.43.
- Status
-
vulnerable
Aug 20, 2024
UsersWP – Front-end login form, User Registration, User Profile & Members Directory plugin for WordPress # CVE-2024-43277
- CVE, Research URL
- Date
- Nov 01, 2024
- Research Description
- Missing Authorization vulnerability in AyeCode Ltd UsersWP allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects UsersWP: from n/a through 1.2.15.
- Affected versions
-
max 1.2.16.
- Status
-
vulnerable
Aug 04, 2024
UsersWP – Front-end login form, User Registration, User Profile & Members Directory plugin for WordPress # CVE-2024-6477
- CVE, Research URL
- Date
- Aug 03, 2024
- Research Description
- The UsersWP WordPress plugin before 1.2.12 uses predictable filenames when an admin generates an export, which could allow unauthenticated attackers to download them and retrieve sensitive information such as IP, username, and email address
- Affected versions
-
max 1.2.12.
- Status
-
vulnerable
Jun 30, 2024
UsersWP – Front-end login form, User Registration, User Profile & Members Directory plugin for WordPress # CVE-2024-6265
- CVE, Research URL
- Date
- Jun 29, 2024
- Research Description
- The UsersWP – Front-end login form, User Registration, User Profile & Members Directory plugin for WordPress plugin for WordPress is vulnerable to time-based SQL Injection via the ‘uwp_sort_by’ parameter in all versions up to, and including, 1.2.10 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for unauthenticated attackers to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database.
- Affected versions
-
max 1.2.11.
- Status
-
vulnerable
Jun 06, 2024
UsersWP – Front-end login form, User Registration, User Profile & Members Directory plugin for WordPress # CVE-2022-0442
- CVE, Research URL
- Date
- Mar 07, 2022
- Research Description
- The UsersWP WordPress plugin before 1.2.3.1 is missing access controls when updating a user avatar, and does not make sure file names for user avatars are unique, allowing a logged in user to overwrite another users avatar.
- Affected versions
-
max 1.2.3.10.
- Status
-
vulnerable
UsersWP – Front-end login form, User Registration, User Profile & Members Directory plugin for WordPress # CVE-2022-47442
- CVE, Research URL
- Date
- Nov 07, 2023
- Research Description
- Improper Neutralization of Formula Elements in a CSV File vulnerability in AyeCode Ltd UsersWP.This issue affects UsersWP: from n/a through 1.2.3.9.
- Affected versions
-
max 1.2.3.23.
- Status
-
vulnerable
UsersWP – Front-end login form, User Registration, User Profile & Members Directory plugin for WordPress # CVE-2024-2423
- CVE, Research URL
- Date
- Apr 10, 2024
- Research Description
- The UsersWP – Front-end login form, User Registration, User Profile & Members Directory plugin for WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's shortcode(s) in all versions up to, and including, 1.2.6 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers with contributor-level and above permissions to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.
- Affected versions
-
max 1.2.7.
- Status
-
vulnerable
UsersWP – Front-end login form, User Registration, User Profile & Members Directory plugin for WordPress # CVE-2024-31936
- CVE, Research URL
- Date
- Apr 11, 2024
- Research Description
- Cross-Site Request Forgery (CSRF) vulnerability in AyeCode Ltd UsersWP.This issue affects UsersWP: from n/a before 1.2.6.
- Affected versions
-
max 1.2.6.
- Status
-
vulnerable