
🚨High - UsersWP WordPress Plugin Arbitrary File Deletion (CVE-2026-13492) The UsersWP plugin insufficiently validates file-field values: validate_fields() falls through to sanitize_text_field() for 'file' fields, leaving ../ traversal sequences intact. The upload_file_remove() AJAX handler then builds the delete target from the uploads basedir plus the attacker-controlled metadata value and calls unlink() with no realpath check or uploads-directory boundary. An authenticated attacker with Subscriber-level access or above can delete arbitrary files on the server, including wp-config.php - which typically drops WordPress into the setup flow and enables full site takeover. 👉Update UsersWP beyond 1.2.65 to the patched release.
Post summary
The CVE‑2026‑13492 vulnerability in UsersWP allows authenticated users to delete arbitrary files; updating to a version newer than 1.2.65 resolves the issue.
