PatchSiren cyber security CVE debrief
CVE-2026-18501 stiofansisland CVE debrief
The UsersWP plugin for WordPress, specifically versions up to and including 1.2.69, is vulnerable to stored cross-site scripting via Badge Widget Variable Substitution. This vulnerability allows authenticated attackers with subscriber-level access and above to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. The vulnerability is due to insufficient input sanitization and output escaping. Users of the UsersWP plugin for WordPress should be aware of this vulnerability and take steps to mitigate it, including verifying installed versions, applying vendor remediation when available, and monitoring for suspicious activity.
- Vendor
- stiofansisland
- Product
- UsersWP – Front-end login form, User Registration, User Profile & Members Directory plugin for WP
- CVSS
- MEDIUM 6.4
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-08-06
- Original CVE updated
- 2026-08-06
- Advisory published
- 2026-08-06
- Advisory updated
- 2026-08-06
Who should care
Users of the UsersWP plugin for WordPress, particularly those with subscriber-level access, should be aware of this vulnerability and take steps to mitigate it. This includes verifying installed versions, applying vendor remediation when available, and monitoring for suspicious activity. Security teams should review access controls and ensure that compensating controls are in place for exposed systems.
Technical summary
The UsersWP plugin for WordPress is vulnerable to stored cross-site scripting via Badge Widget Variable Substitution in all versions up to, and including, 1.2.69. This allows authenticated attackers with subscriber-level access and above to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. The vulnerability is due to insufficient input sanitization and output escaping. The plugin's Badge Widget Variable Substitution feature does not properly sanitize user input, allowing attackers to inject malicious scripts.
Defensive priority
Authenticated attackers with subscriber-level access can inject web scripts via the UsersWP plugin's Badge Widget Variable Substitution.
Recommended defensive actions
- Inventory and verify installed version of UsersWP plugin
- Apply vendor remediation when available
- Monitor for suspicious activity
- Restrict access to sensitive areas
- Review access controls and ensure compensating controls are in place for exposed systems
- Verify installed versions and review access controls
- Track exceptions and retest remediated assets
Evidence notes
The UsersWP plugin for WordPress has a stored cross-site scripting vulnerability via Badge Widget Variable Substitution. Authenticated attackers with subscriber-level access can inject web scripts. The CVE record was published on 2026-08-06T14:16:32.290Z. Evidence is limited to public sources and may not reflect the full scope of affected systems. Defenders should verify installed versions, review access controls, and monitor for suspicious activity.
Official resources
AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-08-06T14:16:32.290Z and has not been modified since then.