Impact
The UsersWP WordPress plugin allows an authenticated user with Subscriber or higher privileges to delete arbitrary files on the server. The flaw arises from the upload_file_remove() AJAX handler that accepts a file URL from form input, validates it only with the loose validate_file() function, then normalizes the URL using a global str_replace() that can collapse '..<uploads-baseurl>' tokens into traversal sequences. When the transformed URL is appended to the uploads base directory and passed to wp_delete_file(), no canonical containment check is performed, enabling deletion of any file on the file system. This is a classic path traversal weakness identified as CWE‑22 with a high severity impact on confidentiality, integrity, and availability.
Affected Systems
This vulnerability affects the stiofansisland UsersWP plugin, used for front‑end login forms, user registration, user profiles, and member directories in WordPress installations. Versions up to and including 1.2.70 are impacted; later versions are not listed as vulnerable.
Risk and Exploitability
The CVSS score of 8.1 indicates high severity, and while a specialized EPSS score is not published, the flaw is authenticated and requires only Subscriber-level access, a common role in many sites, making exploitation realistic. The vulnerability is not currently listed in the CISA KEV catalog. Attackers can exploit the weakness by crafting a specially‑formatted URL payload sent through the AJAX endpoint, triggering the deletion of arbitrary files such as wp-config.php. The lack of a published EPSS score suggests the exploitation probability is unknown, but the combination of high severity and wide availability of the required role makes this a pressing concern.
OpenCVE Enrichment