Description
The UsersWP – Front-end login form, User Registration, User Profile & Members Directory plugin for WP plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Badge Widget Variable Substitution in all versions up to, and including, 1.2.69 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with subscriber-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.
Published: 2026-08-06
Score: 6.4 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The UsersWP plugin contains a stored cross‑site scripting vulnerability (CWE‑79) that allows authenticated users with subscriber-level access or higher to inject arbitrary JavaScript into pages via the Badge Widget Variable Substitution feature. Because the input is not properly sanitized and the output is not escaped, any user who loads a page containing the injected content will execute the attacker’s script. This can lead to session hijacking, defacement, or redirection to malicious sites and therefore compromises confidentiality, integrity, and availability of user interactions.

Affected Systems

The vulnerability applies to all versions of the UsersWP plugin up to and including 1.2.69, provided by stiofansisland. Site owners running the plugin at any of these versions are susceptible to the described XSS attack.

Risk and Exploitability

The CVSS base score of 6.4 indicates a moderate severity risk. Attackers must be authenticated with at least subscriber privileges to exploit the flaw, though the impact can affect any visitor who views the contaminated page. The EPSS score is not available, and the vulnerability is not listed in the CISA KEV catalog, suggesting no confirmed exploitation at the time of this analysis.

Generated by OpenCVE AI on August 6, 2026 at 16:59 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Update the UsersWP plugin to the latest version (1.2.70 or later) to apply the vendor‑supplied fix.
  • If an update is not yet available, disable or remove the Badge Widget from user pages to eliminate the vulnerable variable substitution mechanism.
  • Limit subscriber privileges to trusted users and regularly audit role assignments to reduce the attack surface.
  • Monitor site logs for anomalous script injection attempts and review page content for unexpected JavaScript.

Generated by OpenCVE AI on August 6, 2026 at 16:59 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 06 Aug 2026 19:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 06 Aug 2026 18:30:00 +0000

Type Values Removed Values Added
First Time appeared Stiofansisland
Stiofansisland userswp – Front-end Login Form, User Registration, User Profile & Members Directory Plugin For Wp
Wordpress
Wordpress wordpress
Vendors & Products Stiofansisland
Stiofansisland userswp – Front-end Login Form, User Registration, User Profile & Members Directory Plugin For Wp
Wordpress
Wordpress wordpress

Thu, 06 Aug 2026 14:00:00 +0000

Type Values Removed Values Added
Description The UsersWP – Front-end login form, User Registration, User Profile & Members Directory plugin for WP plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Badge Widget Variable Substitution in all versions up to, and including, 1.2.69 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with subscriber-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.
Title UsersWP <= 1.2.69 - Authenticated (Subscriber+) Stored Cross-Site Scripting via Badge Widget Variable Substitution
Weaknesses CWE-79
References
Metrics cvssV3_1

{'score': 6.4, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N'}


Subscriptions

Stiofansisland Userswp – Front-end Login Form, User Registration, User Profile & Members Directory Plugin For Wp
Wordpress Wordpress
cve-icon MITRE

Status: PUBLISHED

Assigner: Wordfence

Published:

Updated: 2026-08-06T18:53:30.872Z

Reserved: 2026-07-31T16:27:36.937Z

Link: CVE-2026-18501

cve-icon Vulnrichment

Updated: 2026-08-06T18:53:27.418Z

cve-icon NVD

Status : Deferred

Published: 2026-08-06T14:16:32.290

Modified: 2026-08-12T21:00:52.257

Link: CVE-2026-18501

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-06T18:15:02Z

Weaknesses
  • CWE-79

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')