UsersWP <= 1.2.58 - Authenticated (Subscriber+) Server-Side Request Forgery via 'uwp_crop' Parameter
UsersWP – Front-end login form, User Registration, User Profile & Members Directory plugin for WP
Minimum safe version
1.2.61
Update to 1.2.61 or later to address 21 fixable vulnerabilities
UsersWP <= 1.2.60 - Authenticated (Subscriber+) Stored Cross-Site Scripting via User Badge Link Substitution
UsersWP <= 1.2.58 - Authenticated (Subscriber+) Restricted Usermeta Modification via 'htmlvar' Parameter
CVE-2026-25015
UsersWP <= 1.2.48 - Cross-Site Request Forgery
UsersWP <= 1.2.47 - Missing Authorization
CVE-2025-10003
WordPress UsersWP Plugin <= 1.2.42 is vulnerable to Cross Site Scripting (XSS)
CVE-2024-43277
WordPress UsersWP Plugin < 1.2.12 is vulnerable to Sensitive Data Exposure
WordPress UsersWP Plugin <= 1.2.10 is vulnerable to SQL Injection
CVE-2024-31936
CVE-2024-2423
UsersWP < 1.2.3.23 - Profile Picture Deletion via CSRF
UsersWP <= 1.2.3.22 - Cross-Site Request Forgery
CVE-2022-47442
UsersWP <= 1.2.3.9 - Authenticated (Administrator+) CSV Injection
WordPress UsersWP – Front-end login form, User Registration, User Profile & Members Directory plugin for WordPress Plugin <= 1.2.3.9 is vulnerable to CSV Injection
UsersWP – User Registration & User Profile <= 1.2.2.28 - Reflected Cross-Site Scripting
wpscan.com
CVE-2022-0442