Cross-site Scripting Vulnerability in Ren Ventura WP Delete User Accounts Plugin
CVE-2025-26906
6.5MEDIUM
What is CVE-2025-26906?
The Ren Ventura WP Delete User Accounts plugin is susceptible to a Cross-site Scripting (XSS) vulnerability due to improper input handling during web page generation. This flaw allows attackers to exploit DOM-based XSS, potentially compromising user session data and executing malicious scripts in the context of a user's browser. Users of the plugin are encouraged to update to the latest version to mitigate this security risk.
Affected Version(s)
WP Delete User Accounts <= 1.2.3