Impact
The UsersWP plugin contains a stored cross‑site scripting vulnerability (CWE‑79) that allows authenticated users with subscriber-level access or higher to inject arbitrary JavaScript into pages via the Badge Widget Variable Substitution feature. Because the input is not properly sanitized and the output is not escaped, any user who loads a page containing the injected content will execute the attacker’s script. This can lead to session hijacking, defacement, or redirection to malicious sites and therefore compromises confidentiality, integrity, and availability of user interactions.
Affected Systems
The vulnerability applies to all versions of the UsersWP plugin up to and including 1.2.69, provided by stiofansisland. Site owners running the plugin at any of these versions are susceptible to the described XSS attack.
Risk and Exploitability
The CVSS base score of 6.4 indicates a moderate severity risk. Attackers must be authenticated with at least subscriber privileges to exploit the flaw, though the impact can affect any visitor who views the contaminated page. The EPSS score is not available, and the vulnerability is not listed in the CISA KEV catalog, suggesting no confirmed exploitation at the time of this analysis.
OpenCVE Enrichment