CVE-2026-13492Patch

LOWCVSS 8.8 · HIGH

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch affected systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

The UsersWP plugin for WordPress is vulnerable to Arbitrary File Deletion in versions up to, and including, 1.2.65. This is due to insufficient validation of file-field values in the UsersWP_Validation::validate_fields() function (which falls through to sanitize_text_field() for fields of type 'file', leaving directory-traversal sequences intact) combined with the UsersWP_Forms::upload_file_remove() AJAX handler building the deletion target from the uploads basedir concatenated with the attacker-controlled metadata value without any realpath canonicalization or uploads-directory boundary check before calling unlink(). This makes it possible for authenticated attackers, with Subscriber-level access and above, to delete arbitrary files on the affected site's server, including wp-config.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-22

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

NONE

Threat summary

  • Patch or workaround signal is available
  • 1 mentions across 1 observed day

What's happening

  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 1 signal
  • 1 total mentions across 1 day

Deep dive

Activity timeline1 mentions / 1d
00111Mentions · 2026-07-10: 1Patch / Workaround · 2026-07-10: 1Technical Details · 2026-07-10: 107-10
Signal classification1 categories
Patch
1100.0%
Full discourse1 post
  • Upwind Security MDR@UpwindMDR
    Patch

    🚨High - UsersWP WordPress Plugin Arbitrary File Deletion (CVE-2026-13492) The UsersWP plugin insufficiently validates file-field values: validate_fields() falls through to sanitize_text_field() for 'file' fields, leaving ../ traversal sequences intact. The upload_file_remove() AJAX handler then builds the delete target from the uploads basedir plus the attacker-controlled metadata value and calls unlink() with no realpath check or uploads-directory boundary. An authenticated attacker with Subscriber-level access or above can delete arbitrary files on the server, including wp-config.php - which typically drops WordPress into the setup flow and enables full site takeover. 👉Update UsersWP beyond 1.2.65 to the patched release.

    Post summary

    The CVE‑2026‑13492 vulnerability in UsersWP allows authenticated users to delete arbitrary files; updating to a version newer than 1.2.65 resolves the issue.

    0000076
    246 followersView on X

Explore more