Software intelligence
Important: Userswp appearing in this catalog does not mean your website is affected. Exposure depends on your installed version. How SiteRespond intelligence works
Tracked advisories
21
Latest advisory
6 August 2026
CISA KEV matches
0
In this WordPress feed
WordPress slug
userswp
Plugin
This catalog lists 21 known advisories affecting Userswp. The most recent was published on 6 August 2026. If you use this software, compare your installed version against the affected ranges on each advisory and update to a fixed release outside those ranges. SiteRespond Defence checks your actual installed version when the plugin is connected — listing here does not by itself mean your site is vulnerable.
UsersWP <= 1.2.69 - Authenticated (Subscriber+) Stored Cross-Site Scripting via Badge Widget Variable Substitution
May allow attackers to run scripts in visitors' browsers or hijack admin sessions.
Published 6 August 2026
UsersWP <= 1.2.65 - Authenticated (Subscriber+) Arbitrary File Deletion via File Upload Field
May allow attackers to run arbitrary code on the server if exploited.
Published 9 July 2026
UsersWP – Front-end login form, User Registration, User Profile & Members Directory plugin for WP < 1.2.67 - Two-Factor Authentication Bypass
May allow access to accounts or admin areas without valid credentials.
Published 8 July 2026
Known Userswp advisories published by month.
CVE-2024-31936 · Published 10 April 2024
Affected versions: ≤ 1.2.4
CVE-2024-2423 · Published 14 March 2024
Affected versions: ≤ 1.2.6
No CVE assigned · Published 1 November 2023
Affected versions: < 1.2.3.23
CVE-2022-47442 · Published 21 December 2022
Affected versions: ≤ 1.2.3.9
CVE-2022-0442 · Published 14 February 2022
Affected versions: < 1.2.3.1
No CVE assigned · Published 6 September 2021
Affected versions: ≤ 1.2.2.28
SiteRespond Defence matches your installed Userswp version against this catalog when the Defence plugin is connected to your WordPress site.