SQL Injection Vulnerability in UsersWP Plugin for WordPress
CVE-2025-10003

6.5MEDIUM

What is CVE-2025-10003?

The UsersWP plugin for WordPress is susceptible to a time-based SQL Injection vulnerability. The flaw resides in the 'upload_file_remove' function and the 'htmlvar' parameter across all versions up to 1.2.44. Due to inadequate escaping of user input and insufficient preparation of the SQL query, unauthenticated attackers may exploit this vulnerability to inject additional SQL queries. This could potentially allow them to extract sensitive information from the underlying database, posing significant security risks to WordPress sites utilizing this plugin.

Affected Version(s)

UsersWP – Front-end login form, User Registration, User Profile & Members Directory plugin for WP * <= 1.2.44

References

CVSS V3.1

Score:
6.5
Severity:
MEDIUM
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Nguyen Ngoc Quang Bach
.
CVE-2025-10003 : SQL Injection Vulnerability in UsersWP Plugin for WordPress