CVE-2026-18501: UsersWP <= 1.2.69 - Authenticated (Subscriber+) Stored Cross-Site Scripting via Badge Widget Variable Substitution
The UsersWP – Front-end login form, User Registration, User Profile & Members Directory plugin for WP plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Badge Widget Variable Substitution in all versions up to, and including, 1.2.69 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with subscriber-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
UsersWP – Front-end login form, User Registration, User Profile & Members Directory plugin for WordPressto a version that resolves this vulnerability.Fixed in 1.2.69
Event History
Frequently Asked Questions
What is the severity of CVE-2026-18501?
CVE-2026-18501 has a medium severity rating of 6.4.
How do I fix CVE-2026-18501?
To fix CVE-2026-18501, upgrade to the latest version of UsersWP that exceeds version 1.2.69.
What type of vulnerability is CVE-2026-18501?
CVE-2026-18501 is classified as a Stored Cross-Site Scripting (XSS) vulnerability.
Who is affected by CVE-2026-18501?
CVE-2026-18501 affects all users of the UsersWP plugin for WordPress up to and including version 1.2.69.
What can happen if CVE-2026-18501 is exploited?
If exploited, CVE-2026-18501 can allow attackers to execute arbitrary scripts in the context of user sessions.