PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-18501 stiofansisland CVE debrief

The UsersWP plugin for WordPress, specifically versions up to and including 1.2.69, is vulnerable to stored cross-site scripting via Badge Widget Variable Substitution. This vulnerability allows authenticated attackers with subscriber-level access and above to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. The vulnerability is due to insufficient input sanitization and output escaping. Users of the UsersWP plugin for WordPress should be aware of this vulnerability and take steps to mitigate it, including verifying installed versions, applying vendor remediation when available, and monitoring for suspicious activity.

Vendor
stiofansisland
Product
UsersWP – Front-end login form, User Registration, User Profile & Members Directory plugin for WP
CVSS
MEDIUM 6.4
CISA KEV
Not listed in stored evidence
Original CVE published
2026-08-06
Original CVE updated
2026-08-06
Advisory published
2026-08-06
Advisory updated
2026-08-06

Who should care

Users of the UsersWP plugin for WordPress, particularly those with subscriber-level access, should be aware of this vulnerability and take steps to mitigate it. This includes verifying installed versions, applying vendor remediation when available, and monitoring for suspicious activity. Security teams should review access controls and ensure that compensating controls are in place for exposed systems.

Technical summary

The UsersWP plugin for WordPress is vulnerable to stored cross-site scripting via Badge Widget Variable Substitution in all versions up to, and including, 1.2.69. This allows authenticated attackers with subscriber-level access and above to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. The vulnerability is due to insufficient input sanitization and output escaping. The plugin's Badge Widget Variable Substitution feature does not properly sanitize user input, allowing attackers to inject malicious scripts.

Defensive priority

Authenticated attackers with subscriber-level access can inject web scripts via the UsersWP plugin's Badge Widget Variable Substitution.

Recommended defensive actions

  • Inventory and verify installed version of UsersWP plugin
  • Apply vendor remediation when available
  • Monitor for suspicious activity
  • Restrict access to sensitive areas
  • Review access controls and ensure compensating controls are in place for exposed systems
  • Verify installed versions and review access controls
  • Track exceptions and retest remediated assets

Evidence notes

The UsersWP plugin for WordPress has a stored cross-site scripting vulnerability via Badge Widget Variable Substitution. Authenticated attackers with subscriber-level access can inject web scripts. The CVE record was published on 2026-08-06T14:16:32.290Z. Evidence is limited to public sources and may not reflect the full scope of affected systems. Defenders should verify installed versions, review access controls, and monitor for suspicious activity.

Official resources

AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-08-06T14:16:32.290Z and has not been modified since then.