{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/products/userswp--1.2.70/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":["cpe:2.3:a:userswp:userswp:*:*:*:*:*:*:*:*"],"_cs_cves":[{"cvss":8.1,"id":"CVE-2026-19991"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["UsersWP (\u003c= 1.2.70)"],"_cs_severities":["high"],"_cs_tags":[],"_cs_type":"advisory","_cs_vendors":["UsersWP"],"content_html":"\u003cp\u003eThe UsersWP WordPress plugin (versions 1.2.70 and below) contains an arbitrary file deletion vulnerability (CVE-2026-19991) triggered via the upload_file_remove() AJAX handler. The vulnerability stems from improper validation of user-supplied file path input. The plugin incorrectly validates inputs intended for file removal, as it fails to account for normalized path traversal sequences that emerge after processing. Specifically, when an attacker provides a crafted URL containing embedded upload base URL tokens, the plugin's helper function performs a global string replacement, transforming the input into a directory traversal sequence ('../../'). This path is then appended to the uploads base directory and passed to wp_delete_file() without canonicalization or containment checks. An authenticated attacker with at least Subscriber-level access can exploit this to remove sensitive files from the WordPress installation, including wp-config.php, which could lead to service disruption or site takeover.\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation allows an authenticated attacker to delete any file on the web server that the web server user has permission to modify. This can lead to the deletion of wp-config.php, forcing a site reinstallation, or other critical files, resulting in a denial-of-service condition or site compromise. The vulnerability affects all WordPress sites utilizing UsersWP version 1.2.70 or lower.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eUpgrade the UsersWP plugin to a version higher than 1.2.70 immediately to remediate CVE-2026-19991.\u003c/li\u003e\n\u003cli\u003eImplement a Web Application Firewall (WAF) rule to block POST requests containing path traversal sequences (e.g., '../') targeted at the AJAX handlers used by the plugin.\u003c/li\u003e\n\u003cli\u003eAudit logs for unauthorized deletion attempts or anomalous file system activity originating from low-privileged Subscriber accounts.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-09-11T05:12:05Z","date_published":"2026-09-11T05:12:05Z","id":"https://feed.craftedsignal.io/briefs/2026-09-userswp-afd/","summary":"The UsersWP plugin for WordPress versions up to 1.2.70 allows authenticated attackers to delete arbitrary files on the web server via a path traversal vulnerability in the upload_file_remove() AJAX handler.","title":"Arbitrary File Deletion in UsersWP WordPress Plugin","url":"https://feed.craftedsignal.io/briefs/2026-09-userswp-afd/"}],"language":"en","title":"CraftedSignal Threat Feed - UsersWP (\u003c= 1.2.70)","version":"https://jsonfeed.org/version/1.1"}