Vendor
high
advisory
Arbitrary File Deletion in UsersWP WordPress Plugin
1 rule 1 TTP 1 CVEThe UsersWP plugin for WordPress versions up to 1.2.70 allows authenticated attackers to delete arbitrary files on the web server via a path traversal vulnerability in the upload_file_remove() AJAX handler.
UsersWP
1r
1t
1c
high
advisory
UsersWP Plugin Arbitrary File Deletion (CVE-2026-13492)
1 rule 3 TTPs 1 CVEThe UsersWP plugin for WordPress contains an Arbitrary File Deletion vulnerability, CVE-2026-13492, in versions up to and including 1.2.65, allowing an authenticated attacker with Subscriber-level access or higher to exploit insufficient validation in file-field values combined with an AJAX handler that lacks proper path canonicalization to delete arbitrary files on the server, including critical files like `wp-config.php`, leading to system impact.
UsersWP plugin <= 1.2.65 +1
wordpress
plugin
vulnerability
web
file-deletion
remote-code-execution
1r
3t
1c