6.4
/ 10
MEDIUM
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N
Description
The UsersWP plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to and including 1.2.60. This is due to insufficient input sanitization of user-supplied URL fields and improper output escaping when rendering user profile data in badge widgets. This makes it possible for authenticated attackers, with subscriber-level access and above, to inject arbitrary web scripts that will execute whenever a user accesses a page containing the affected badge widget.
Basic Information
ID
CVE-2026-5742
Source
Wordfence
Published
Apr 9, 2026 at 03:25
Modified
Apr 9, 2026 at 14:43
Affected Product
Vendor
stiofansisland
Product
UsersWP – Front-end login form, User Registration, User Profile & Members Directory plugin for WP
Affected Versions
stiofansisland UsersWP – Front-end login form, User Registration, User Profile & Members Directory plugin for WP 0
CWE Classification
References
- www.wordfence.com /threat-intel/vulnerabilities/id/bdb619c5-967c-4b8c-8a93-bcdb49137d56
- plugins.trac.wordpress.org /browser/userswp/trunk/vendor/ayecode/wp-ayecode-ui/includes/components/class-aui-component-button.php
- plugins.trac.wordpress.org /browser/userswp/tags/1.2.55/vendor/ayecode/wp-ayecode-ui/includes/components/class-aui-component-button.php
- plugins.trac.wordpress.org /browser/userswp/trunk/includes/helpers/pages.php
- plugins.trac.wordpress.org /browser/userswp/tags/1.2.55/includes/helpers/pages.php
- plugins.trac.wordpress.org /browser/userswp/trunk/includes/helpers/pages.php
- plugins.trac.wordpress.org /browser/userswp/tags/1.2.55/includes/helpers/pages.php
- plugins.trac.wordpress.org /browser/userswp/trunk/includes/class-forms.php
- plugins.trac.wordpress.org /browser/userswp/tags/1.2.55/includes/class-forms.php
- plugins.trac.wordpress.org /changeset