PatchSiren

stiofansisland CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

HIGH stiofansisland CVE published 2026-09-11

CVE-2026-19991

The UsersWP plugin for WordPress has a vulnerability allowing authenticated attackers with Subscriber-level access to delete arbitrary files on the server. This is due to insufficient validation and normalization of user-supplied file paths. The vulnerability exists in versions up to and including 1.2.70 of the UsersWP plugin. An attacker can exploit this by providing a crafted file path that can be norma [truncated]

MEDIUM stiofansisland CVE published 2026-08-06

CVE-2026-18501

The UsersWP plugin for WordPress, specifically versions up to and including 1.2.69, is vulnerable to stored cross-site scripting via Badge Widget Variable Substitution. This vulnerability allows authenticated attackers with subscriber-level access and above to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. The vulnerability is due to insufficient input s [truncated]

MEDIUM stiofansisland CVE published 2026-08-01

CVE-2026-17605

The Payment forms, Buy now buttons, and Invoicing System | GetPaid plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 2.8.56 via the getpaid_payment_form_element function. This makes it possible for authenticated attackers, with administrator-level access and above, to include and execute arbitrary .php files on the server, allowing the execution of any PHP co [truncated]

HIGH stiofansisland CVE published 2026-07-09

CVE-2026-13492

The UsersWP plugin for WordPress is vulnerable to Arbitrary File Deletion in versions up to, and including, 1.2.65. This is due to insufficient validation of file-field values in the UsersWP_Validation::validate_fields() function combined with the UsersWP_Forms::upload_file_remove() AJAX handler building the deletion target without realpath canonicalization or uploads-directory boundary check.

LOW stiofansisland CVE published 2026-06-18

CVE-2026-12102

The UsersWP – Front-end login form, User Registration, User Profile & Members Directory plugin for WP plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 1.2.63 via the 'user_id' parameter due to missing validation on a user controlled key. This vulnerability allows authenticated attackers, with editor-level access and above, to reset and permanentl [truncated]

HIGH stiofansisland CVE published 2026-06-09

CVE-2026-11616

The Events Calendar for GeoDirectory plugin for WordPress is vulnerable to Privilege Escalation in versions up to and including 2.3.28. This is due to the ajax_ayi_action() handler only applying strip_tags(esc_sql()) — with no allow-list — to the attacker-controlled $_POST['type'] and $_POST['postid'] values before forwarding them to update_ayi_data(), which calls update_user_meta($current_user->ID, $rsvp [truncated]