Extension WordPress
Vulnérabilités UsersWP – Front-end login form, User Registration, User Profile & Members Directory plugin for WP
Cette page rassemble les failles publiées pour UsersWP – Front-end login form, User Registration, User Profile & Members Directory plugin for WP, leurs plages de versions affectées et les correctifs signalés dans la base locale.
Historique de sécurité
CVE et vulnérabilités de UsersWP – Front-end login form, User Registration, User Profile & Members Directory plugin for WP
19 fiches
UsersWP <= 1.2.65 – Authenticated (Subscriber+) Arbitrary File Deletion via File Upload Field
The UsersWP plugin for WordPress is vulnerable to Arbitrary File Deletion in versions up to, and including, 1.2.65. This is due to insufficient validation of file-field values in the UsersWP_Validation::validate_fields() function (which falls through to sanitize_text_field() for fields…
*-1.2.65
1.2.66
09/07/2026
UsersWP <= 1.2.63 – Insecure Direct Object Reference to Authenticated (Editor+) Arbitrary User Avatar/Banner Reset via 'user_id' Parameter
The UsersWP – Front-end login form, User Registration, User Profile & Members Directory plugin for WP plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 1.2.63 via the 'user_id' parameter…
*-1.2.63
1.2.64
17/06/2026
UsersWP <= 1.2.58 – Authenticated (Subscriber+) Server-Side Request Forgery via 'uwp_crop' Parameter
The UsersWP – Front-end login form, User Registration, User Profile & Members Directory plugin for WP plugin for WordPress is vulnerable to blind Server-Side Request Forgery in all versions up to, and including, 1.2.58. This is due to…
*-1.2.58
1.2.59
10/04/2026
UsersWP <= 1.2.58 – Authenticated (Subscriber+) Restricted Usermeta Modification via 'htmlvar' Parameter
The UsersWP – Front-end login form, User Registration, User Profile & Members Directory plugin for WordPress is vulnerable to Improper Access Control in all versions up to, and including, 1.2.58 This is due to insufficient field-level permission validation…
*-1.2.58
1.2.59
09/04/2026
UsersWP <= 1.2.60 – Authenticated (Subscriber+) Stored Cross-Site Scripting via User Badge Link Substitution
The UsersWP plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to and including 1.2.60. This is due to insufficient input sanitization of user-supplied URL fields and improper output escaping when rendering user profile data…
*-1.2.60
1.2.61
08/04/2026
UsersWP <= 1.2.53 – Cross-Site Request Forgery
The UsersWP – Front-end login form, User Registration, User Profile & Members Directory plugin for WP plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.2.53. This is due to missing…
*-1.2.53
1.2.54
28/01/2026
UsersWP <= 1.2.48 – Cross-Site Request Forgery
The UsersWP – Front-end login form, User Registration, User Profile & Members Directory plugin for WP plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.2.48. This is due to missing…
*-1.2.48
1.2.49
15/12/2025
UsersWP <= 1.2.47 – Missing Authorization
The UsersWP – Front-end login form, User Registration, User Profile & Members Directory plugin for WP plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in all versions up to,…
*-1.2.47
1.2.48
25/11/2025
UsersWP – Front-end login form, User Registration, User Profile & Members Directory plugin for WP <= 1.2.44 – Authenticated (Subscriber+) SQL Injection
The UsersWP – Front-end login form, User Registration, User Profile & Members Directory plugin for WordPress plugin for WordPress is vulnerable to time-based SQL Injection via the ‘upload_file_remove’ function and 'htmlvar' parameter in all versions up to, and…
*-1.2.44
1.2.45
05/09/2025
UsersWP <= 1.2.42 – Authenticated (Contributor+) Stored Cross-Site Scripting
The UsersWP – Front-end login form, User Registration, User Profile & Members Directory plugin for WP plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'uwp_profile' and 'uwp_profile_header' shortcodes in all versions up to, and…
*-1.2.42
1.2.43
27/08/2025
UsersWP <= 1.2.15 – Missing Authorization
The UsersWP plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the activation_redirect() function in versions up to, and including, 1.2.15. This makes it possible for unauthenticated attackers to trigger…
*-1.2.15
1.2.16
16/08/2024
UsersWP – Front-end login form, User Registration, User Profile & Members Directory plugin for WP <= 1.2.11 – Unauthenticated Information Disclosure via Unprotected Directories
The UsersWP – Front-end login form, User Registration, User Profile & Members Directory plugin for WP plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 1.2.11due to insufficient protections on the…
*-1.2.11
1.2.12
13/07/2024
UsersWP – Front-end login form, User Registration, User Profile & Members Directory plugin for WordPress <= 1.2.10 – Unauthenticated SQL Injection via 'uwp_sort_by'
The UsersWP – Front-end login form, User Registration, User Profile & Members Directory plugin for WordPress plugin for WordPress is vulnerable to time-based SQL Injection via the ‘uwp_sort_by’ parameter in all versions up to, and including, 1.2.10 due…
*-1.2.10
1.2.11
28/06/2024
UsersWP <= 1.2.4 – Cross-Site Request Forgery
The UsersWP – Front-end login form, User Registration, User Profile & Members Directory plugin for WordPress plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.2.4. This is due to missing…
*-1.2.4
1.2.6
10/04/2024
UsersWP <= 1.2.6 – Authenticated(Contributor+) Stored Cross-Site Scripting via Shortcode
The UsersWP – Front-end login form, User Registration, User Profile & Members Directory plugin for WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's shortcode(s) in all versions up to, and including, 1.2.6 due…
*-1.2.6
1.2.7
14/03/2024
UsersWP <= 1.2.3.22 – Cross-Site Request Forgery
The UsersWP – Front-end login form, User Registration, User Profile & Members Directory plugin for WordPress plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to 1.2.3.23 (exclusive). This is due to missing or…
[*, 1.2.3.23)
1.2.3.23
01/11/2023
UsersWP <= 1.2.3.9 – Authenticated (Administrator+) CSV Injection
The UsersWP plugin for WordPress is vulnerable to CSV Injection in versions up to, and including, 1.2.3.9 via the process_users_export function. This allows administrator-level attackers to embed untrusted input into exported CSV files, which can result in code…
*-1.2.3.9
1.2.3.10
21/12/2022
UsersWP <= 1.2.3 – Subscriber+ User Avatar Override
The UsersWP WordPress plugin before 1.2.3.1 is missing access controls when updating a user avatar, and does not make sure file names for user avatars are unique, allowing a logged in user to overwrite another users avatar.
[*, 1.2.3.1)
1.2.3.1
14/02/2022
UsersWP – User Registration & User Profile <= 1.2.2.28 – Reflected Cross-Site Scripting
The UsersWP – User Registration & User Profile plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via several parameters in versions up to, and including, 1.2.2.28 due to insufficient input sanitization and output escaping. This makes it…
*-1.2.2.28
1.2.2.29
06/09/2021
Extensions également surveillés
WP Commander
Rechercher dans toute la base WordPress
Utilisez la recherche globale pour retrouver une extension, un thème, une CVE ou un identifiant de vulnérabilité.