Executive Intelligence Brief
The UsersWP plugin for WordPress is vulnerable to Arbitrary File Deletion in versions up to, and including, 1.2.70. This vulnerability allows authenticated attackers with Subscriber-level access and above to delete arbitrary files on the affected site's server, including critical files like wp-config.php. The vulnerability has a CVSS score of 8.1, indicating a high severity. Immediate patching is recommended to prevent potential exploitation.
Threat Overview
The UsersWP plugin is a popular front-end login form, user registration, user profile, and members directory plugin for WordPress. It has a significant deployment footprint across WordPress sites that require user management and profile features. The plugin's vulnerability to arbitrary file deletion poses a critical risk to WordPress site administrators, as it could allow attackers to delete essential files, potentially leading to site compromise or data loss.
Technical Deep Dive
Vulnerability Classification
The vulnerability is classified as CWE-22, Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal'). This class of vulnerability occurs when a web application does not properly sanitize and validate user input, allowing an attacker to manipulate file paths and access or delete files outside of the intended directory.
Root Cause Analysis
The root cause of this vulnerability lies in the upload_file_remove() AJAX handler in the UsersWP plugin. Specifically, the plugin stores the value of an account 'file' form field taken directly from $_POST when no real $_FILES upload is provided. The stored value is only checked with validate_file(), which passes any string that does not contain a literal '../'. Later, when processed by upload_file_remove(), the value is normalized through uwp_get_file_relative_url(), allowing a crafted URL containing embedded '..wp_delete_file() without any canonical containment check.
Attack Vector & Chain
The attack vector for this vulnerability involves an authenticated attacker with Subscriber-level access and above sending a crafted request to the upload_file_remove() AJAX handler. The request includes a manipulated 'file' field that exploits the path traversal vulnerability, allowing the attacker to delete arbitrary files on the server.
Exploitation Scenario Walkthrough
Scenario: Arbitrary File Deletion via Crafted AJAX Request
Reconnaissance: An attacker identifies a WordPress site using the vulnerable version of the UsersWP plugin. The attacker gains authenticated access to the site with Subscriber-level permissions.
Weaponization: The attacker crafts a malicious AJAX request to the upload_file_remove() handler, including a manipulated 'file' field designed to exploit the path traversal vulnerability.
Delivery & Exploitation: The attacker sends the crafted AJAX request to the vulnerable site. The plugin processes the request, normalizes the file path, and deletes the targeted file without proper validation.
Post-Exploitation: The attacker could use the arbitrary file deletion capability to target critical files, such as wp-config.php, to disrupt site functionality or prepare for further exploitation.
Impact Realization: The final impact could be the deletion of critical files, leading to site compromise, data loss, or denial of service.
Exploitation in the Wild
The vulnerability is not currently being actively exploited. However, given its high severity and the potential for significant impact, there is a high likelihood that attackers will exploit this vulnerability if not promptly patched.
Impact Analysis
Direct Impact
The direct impact of this vulnerability is the ability for authenticated attackers to delete arbitrary files on the affected site's server, including critical configuration files like wp-config.php. This could lead to site compromise, data loss, or operational disruption.
Downstream & Cascading Effects
The downstream effects could include supply chain risk if the compromised site is part of a larger network, regulatory implications due to data exposure, and operational disruption due to site downtime.
Affected Products & Versions
The UsersWP plugin versions up to, and including, 1.2.70 are affected. Administrators should update to a patched version as soon as possible.
Detection & Threat Hunting
Indicators of Compromise
Indicators of compromise may include unusual file deletion activity, logs of suspicious AJAX requests to the upload_file_remove() handler, or reports of site disruptions.
Detection Rules & Signatures
Detection rules could include monitoring for suspicious requests to the upload_file_remove() AJAX handler, anomalies in file access or deletion patterns, and integration with threat intelligence feeds to identify potential exploitation attempts.
Threat Hunting Queries
Threat hunting queries could involve searching logs for requests to the upload_file_remove() handler, analyzing file system changes for unexpected deletions, and reviewing user activity for signs of authenticated attackers.
Remediation & Hardening
Immediate Actions (0-24 hours)
Administrators should immediately update the UsersWP plugin to a patched version (if available) or apply a temporary workaround such as restricting access to the upload_file_remove() AJAX handler.
Short-Term Hardening (1-7 days)
In the short term, additional security controls could include enhanced monitoring of site activity, implementation of a web application firewall (WAF) to detect and block suspicious requests, and review of user permissions to ensure that only necessary users have access to sensitive functionality.
Strategic Recommendations
Strategically, organizations should prioritize regular updates and patching of plugins, implement a robust vulnerability management program, and consider security enhancements such as two-factor authentication and improved logging and monitoring capabilities.
Analyst Assessment
The risk of exploitation is high due to the vulnerability's severity, the potential for significant impact, and the likelihood of attackers targeting this vulnerability. Organizations should prioritize patching and implement additional security measures to mitigate the risk.
Sources
- National Vulnerability Database (NVD) - CVE-2026-19991