Ayecode
Ayecode Userswp: vulnerabilidades y CVE
Ayecode Userswp tiene 21 vulnerabilidades publicadas, 12 de ellas en los últimos 12 meses. 1 son críticas y 0 figuran en el catálogo de explotación activa de CISA.
CVE21
Últimos 12 meses12
Críticas1
Explotadas activamente0
Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología
Últimas vulnerabilidades
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2026-86814 | Alta (8.1) | 0.38% | — | 19 sept 2026 | The UsersWP WordPress plugin before 1.5.10 does not verify that a social login provider has confirmed ownership of an email address before using it to resolve an existing account, allowing unauthenticated attackers to… |
| CVE-2026-19991 | Alta (8.1) | 0.41% | — | 11 sept 2026 | The UsersWP plugin for WordPress is vulnerable to Arbitrary File Deletion in versions up to, and including, 1.2.70 via the upload_file_remove() AJAX handler. The plugin stores the value of an account 'file' form field… |
| CVE-2026-18501 | Media (6.4) | 0.26% | — | 6 ago 2026 | The UsersWP – Front-end login form, User Registration, User Profile & Members Directory plugin for WP plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Badge Widget Variable Substitution in all… |
| CVE-2026-13690 | Alta (7.4) | 0.41% | — | 29 jul 2026 | The UsersWP WordPress plugin before 1.2.67 does not validate the selected authentication provider in its two-factor login handler, allowing an attacker who already knows a user's credentials to bypass the second… |
| CVE-2026-13492 | Alta (8.8) | 0.69% | — | 9 jul 2026 | The UsersWP plugin for WordPress is vulnerable to Arbitrary File Deletion in versions up to, and including, 1.2.65. This is due to insufficient validation of file-field values in the… |
| CVE-2026-12102 | Baja (2.7) | 0.27% | — | 18 jun 2026 | The UsersWP – Front-end login form, User Registration, User Profile & Members Directory plugin for WP plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 1.2.63… |
| CVE-2026-4979 | Media (5) | 0.45% | — | 11 abr 2026 | The UsersWP – Front-end login form, User Registration, User Profile & Members Directory plugin for WP plugin for WordPress is vulnerable to blind Server-Side Request Forgery in all versions up to, and including, 1.2.58.… |
| CVE-2026-4977 | Media (4.3) | 0.40% | — | 10 abr 2026 | The UsersWP – Front-end login form, User Registration, User Profile & Members Directory plugin for WordPress is vulnerable to Improper Access Control in all versions up to, and including, 1.2.58 This is due to… |
| CVE-2026-5742 | Media (6.4) | 0.42% | — | 9 abr 2026 | The UsersWP plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to and including 1.2.60. This is due to insufficient input sanitization of user-supplied URL fields and improper output… |
| CVE-2026-25015 | Media (4.3) | 0.14% | — | 3 feb 2026 | Cross-Site Request Forgery (CSRF) vulnerability in Stiofan UsersWP userswp allows Cross Site Request Forgery.This issue affects UsersWP: from n/a through <= 1.2.53. |
| CVE-2025-67593 | Media (4.3) | 0.12% | — | 9 dic 2025 | Cross-Site Request Forgery (CSRF) vulnerability in Stiofan UsersWP userswp allows Cross Site Request Forgery.This issue affects UsersWP: from n/a through <= 1.2.48. |
| CVE-2025-66072 | Media (5.3) | 0.25% | — | 21 nov 2025 | Missing Authorization vulnerability in Stiofan UsersWP userswp allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects UsersWP: from n/a through <= 1.2.47. |
| CVE-2025-10003 | Media (6.5) | 0.34% | — | 6 sept 2025 | The UsersWP – Front-end login form, User Registration, User Profile & Members Directory plugin for WordPress plugin for WordPress is vulnerable to time-based SQL Injection via the ‘upload_file_remove’ function and… |
| CVE-2025-9344 | Media (6.4) | 0.24% | — | 28 ago 2025 | The UsersWP – Front-end login form, User Registration, User Profile & Members Directory plugin for WP plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'uwp_profile' and… |
| CVE-2024-43277 | Media (5.3) | 0.40% | — | 1 nov 2024 | Missing Authorization vulnerability in AyeCode Ltd UsersWP allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects UsersWP: from n/a through 1.2.15. |
| CVE-2024-6477 | Alta (7.5) | 0.57% | — | 3 ago 2024 | The UsersWP WordPress plugin before 1.2.12 uses predictable filenames when an admin generates an export, which could allow unauthenticated attackers to download them and retrieve sensitive information such as IP,… |
| CVE-2024-6265 | Crítica (9.8) | 2.4% | — | 29 jun 2024 | The UsersWP – Front-end login form, User Registration, User Profile & Members Directory plugin for WordPress plugin for WordPress is vulnerable to time-based SQL Injection via the ‘uwp_sort_by’ parameter in all versions… |
| CVE-2024-31936 | Media (5.4) | 0.20% | — | 11 abr 2024 | Cross-Site Request Forgery (CSRF) vulnerability in AyeCode Ltd UsersWP.This issue affects UsersWP: from n/a before 1.2.6. |
| CVE-2024-2423 | Media (6.4) | 0.45% | — | 9 abr 2024 | The UsersWP – Front-end login form, User Registration, User Profile & Members Directory plugin for WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's shortcode(s) in all… |
| CVE-2022-47442 | Alta (8.8) | 0.68% | — | 7 nov 2023 | Improper Neutralization of Formula Elements in a CSV File vulnerability in AyeCode Ltd UsersWP.This issue affects UsersWP: from n/a through 1.2.3.9. |
| CVE-2022-0442 | Media (4.3) | 0.65% | — | 7 mar 2022 | The UsersWP WordPress plugin before 1.2.3.1 is missing access controls when updating a user avatar, and does not make sure file names for user avatars are unique, allowing a logged in user to overwrite another users… |
🎯 Cómo se explota (técnicas ATT&CK)
Número de CVE de esta tecnología asignadas a cada técnica de explotación o de impacto principal.