Description
The UsersWP plugin for WordPress is vulnerable to Arbitrary File Deletion in versions up to, and including, 1.2.70 via the upload_file_remove() AJAX handler. The plugin stores the value of an account 'file' form field taken directly from $_POST when no real $_FILES upload is provided (process_account() calls uwp_validate_fields() and array_merges the result with the empty output of UsersWP_Files::validate_uploads()). At storage time the value is only checked with validate_file(), which passes any string that does not contain a literal '../'. When the value is later processed by upload_file_remove(), it is again gated with validate_file() and then normalized through uwp_get_file_relative_url(); that helper performs a global str_replace() of the uploads base URL against the stored URL, allowing a crafted URL containing embedded '..<uploads-baseurl>' tokens to collapse into '../../' traversal sequences after the last validation. The transformed value is then appended to the uploads base directory and passed to wp_delete_file() without any canonical containment check. This makes it possible for authenticated attackers, with Subscriber-level access and above, to delete arbitrary files on the affected site's server (including wp-config.
Published: 2026-09-11
Score: 8.1 High
EPSS: < 1% Very Low
KEV: No
Impact: Arbitrary File Deletion
Action: Patch
AI Analysis

Impact

The UsersWP WordPress plugin allows an authenticated user with Subscriber or higher privileges to delete arbitrary files on the server. The flaw arises from the upload_file_remove() AJAX handler that accepts a file URL from form input, validates it only with the loose validate_file() function, then normalizes the URL using a global str_replace() that can collapse '..<uploads-baseurl>' tokens into traversal sequences. When the transformed URL is appended to the uploads base directory and passed to wp_delete_file(), no canonical containment check is performed, enabling deletion of any file on the file system. This is a classic path traversal weakness identified as CWE‑22 with a high severity impact on confidentiality, integrity, and availability.

Affected Systems

This vulnerability affects the stiofansisland UsersWP plugin, used for front‑end login forms, user registration, user profiles, and member directories in WordPress installations. Versions up to and including 1.2.70 are impacted; later versions are not listed as vulnerable.

Risk and Exploitability

The CVSS score of 8.1 indicates high severity, and while a specialized EPSS score is not published, the flaw is authenticated and requires only Subscriber-level access, a common role in many sites, making exploitation realistic. The vulnerability is not currently listed in the CISA KEV catalog. Attackers can exploit the weakness by crafting a specially‑formatted URL payload sent through the AJAX endpoint, triggering the deletion of arbitrary files such as wp-config.php. The lack of a published EPSS score suggests the exploitation probability is unknown, but the combination of high severity and wide availability of the required role makes this a pressing concern.

Generated by OpenCVE AI on September 11, 2026 at 05:38 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade UsersWP to the latest release that removes the security flaw.
  • If an immediate upgrade is not possible, restrict Subscriber-level users from accessing the upload_file_remove() AJAX endpoint or remove the ability to delete uploaded files via the plugin settings.
  • Consider implementing additional file system permission restrictions or a web application firewall rule that blocks requests containing '..' sequences in file deletion URLs.

Generated by OpenCVE AI on September 11, 2026 at 05:38 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 11 Sep 2026 23:45:00 +0000

Type Values Removed Values Added
First Time appeared Stiofansisland
Stiofansisland userswp – Front-end Login Form, User Registration, User Profile & Members Directory Plugin For Wp
Wordpress
Wordpress wordpress
Vendors & Products Stiofansisland
Stiofansisland userswp – Front-end Login Form, User Registration, User Profile & Members Directory Plugin For Wp
Wordpress
Wordpress wordpress
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Fri, 11 Sep 2026 04:00:00 +0000

Type Values Removed Values Added
Description The UsersWP plugin for WordPress is vulnerable to Arbitrary File Deletion in versions up to, and including, 1.2.70 via the upload_file_remove() AJAX handler. The plugin stores the value of an account 'file' form field taken directly from $_POST when no real $_FILES upload is provided (process_account() calls uwp_validate_fields() and array_merges the result with the empty output of UsersWP_Files::validate_uploads()). At storage time the value is only checked with validate_file(), which passes any string that does not contain a literal '../'. When the value is later processed by upload_file_remove(), it is again gated with validate_file() and then normalized through uwp_get_file_relative_url(); that helper performs a global str_replace() of the uploads base URL against the stored URL, allowing a crafted URL containing embedded '..<uploads-baseurl>' tokens to collapse into '../../' traversal sequences after the last validation. The transformed value is then appended to the uploads base directory and passed to wp_delete_file() without any canonical containment check. This makes it possible for authenticated attackers, with Subscriber-level access and above, to delete arbitrary files on the affected site's server (including wp-config.
Title UsersWP <= 1.2.70 - Authenticated (Subscriber+) Arbitrary File Deletion
Weaknesses CWE-22
References
Metrics cvssV3_1

{'score': 8.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H'}


Subscriptions

Stiofansisland Userswp – Front-end Login Form, User Registration, User Profile & Members Directory Plugin For Wp
Wordpress Wordpress
cve-icon MITRE

Status: PUBLISHED

Assigner: Wordfence

Published:

Updated: 2026-09-11T20:30:39.441Z

Reserved: 2026-08-16T17:24:16.224Z

Link: CVE-2026-19991

cve-icon Vulnrichment

Updated: 2026-09-11T16:31:54.776Z

cve-icon NVD

Status : Deferred

Published: 2026-09-11T04:17:34.990

Modified: 2026-09-11T21:17:09.150

Link: CVE-2026-19991

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-11T18:00:15Z

Weaknesses
  • CWE-22

    Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')