Arbitrary File Deletion in UsersWP Plugin for WordPress
CVE-2026-19991
Key Information:
- Vendor
WordPress
- Status
- Vendor
- CVE Published:
- 11 September 2026
What is CVE-2026-19991?
The UsersWP plugin for WordPress is susceptible to a severe security flaw that allows authenticated users to perform arbitrary file deletions on the server. This vulnerability arises from inadequate validation of file uploads. The vulnerability exists in versions up to and including 1.2.70, where the process for handling account file fields does not sufficiently verify the integrity of file paths. Subpar validation checks allow attackers with Subscriber-level access or higher to exploit crafted file removal requests, potentially resulting in the deletion of critical files like wp-config. Proper containment measures are essential to mitigate this risk.
Affected Version(s)
UsersWP β Front-end login form, User Registration, User Profile & Members Directory plugin for WP 0 <= 1.2.70