Arbitrary File Deletion in UsersWP Plugin for WordPress
CVE-2026-19991

8.1HIGH

What is CVE-2026-19991?

The UsersWP plugin for WordPress is susceptible to a severe security flaw that allows authenticated users to perform arbitrary file deletions on the server. This vulnerability arises from inadequate validation of file uploads. The vulnerability exists in versions up to and including 1.2.70, where the process for handling account file fields does not sufficiently verify the integrity of file paths. Subpar validation checks allow attackers with Subscriber-level access or higher to exploit crafted file removal requests, potentially resulting in the deletion of critical files like wp-config. Proper containment measures are essential to mitigate this risk.

Affected Version(s)

UsersWP – Front-end login form, User Registration, User Profile & Members Directory plugin for WP 0 <= 1.2.70

References

CVSS V3.1

Score:
8.1
Severity:
HIGH
Confidentiality:
None
Integrity:
High
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

daroo
.