VYPR

Userswp

by Ayecode

Source repositories

CVEs (10)

  • CVE-2024-6265CriJun 29, 2024
    risk 0.57cvss 9.8epss 0.02

    The UsersWP – Front-end login form, User Registration, User Profile & Members Directory plugin for WordPress plugin for WordPress is vulnerable to time-based SQL Injection via the ‘uwp_sort_by’ parameter in all versions up to, and including, 1.2.10 due to insufficient…

  • CVE-2026-13492HigJul 9, 2026
    risk 0.50cvss 8.8epss 0.01

    The UsersWP plugin for WordPress is vulnerable to Arbitrary File Deletion in versions up to, and including, 1.2.65. This is due to insufficient validation of file-field values in the UsersWP_Validation::validate_fields() function (which falls through to sanitize_text_field() for…

  • CVE-2024-6477HigAug 3, 2024
    risk 0.49cvss 7.5epss 0.01

    The UsersWP WordPress plugin before 1.2.12 uses predictable filenames when an admin generates an export, which could allow unauthenticated attackers to download them and retrieve sensitive information such as IP, username, and email address

  • CVE-2024-2423MedApr 9, 2024
    risk 0.42cvss 6.4epss 0.00

    The UsersWP – Front-end login form, User Registration, User Profile & Members Directory plugin for WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's shortcode(s) in all versions up to, and including, 1.2.6 due to insufficient input…

  • CVE-2022-47442MedNov 7, 2023
    risk 0.38cvss 5.8epss 0.01

    Improper Neutralization of Formula Elements in a CSV File vulnerability in AyeCode Ltd UsersWP.This issue affects UsersWP: from n/a through 1.2.3.9.

  • CVE-2025-9344MedAug 28, 2025
    risk 0.35cvss 6.4epss 0.00

    The UsersWP – Front-end login form, User Registration, User Profile & Members Directory plugin for WP plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'uwp_profile' and 'uwp_profile_header' shortcodes in all versions up to, and including,…

  • CVE-2024-31936MedApr 11, 2024
    risk 0.28cvss 5.4epss 0.00

    Cross-Site Request Forgery (CSRF) vulnerability in AyeCode Ltd UsersWP.This issue affects UsersWP: from n/a before 1.2.6.

  • CVE-2022-0442MedMar 7, 2022
    risk 0.28cvss 4.3epss 0.01

    The UsersWP WordPress plugin before 1.2.3.1 is missing access controls when updating a user avatar, and does not make sure file names for user avatars are unique, allowing a logged in user to overwrite another users avatar.

  • CVE-2026-4979MedApr 11, 2026
    risk 0.26cvss 5.0epss 0.00

    The UsersWP – Front-end login form, User Registration, User Profile & Members Directory plugin for WP plugin for WordPress is vulnerable to blind Server-Side Request Forgery in all versions up to, and including, 1.2.58. This is due to insufficient URL origin validation in the…

  • CVE-2026-12102LowJun 18, 2026
    risk 0.11cvss 2.7epss 0.00

    The UsersWP – Front-end login form, User Registration, User Profile & Members Directory plugin for WP plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 1.2.63 via the 'user_id' parameter due to missing validation on a…