Column 1
Skip to content

UsersWP CVE-2026-19991: Update and Review Account Access

September 11, 2026

Maintenance priority: If your WordPress site uses UsersWP, review its installed version and arrange an update if it is 1.2.70 or earlier. The Wordfence CNA record for CVE-2026-19991 describes an arbitrary file-deletion vulnerability requiring an authenticated account with Subscriber-level access or higher. This is a UsersWP plugin issue, not a WordPress-core vulnerability and not an unauthenticated remote-code-execution advisory.

Scope: Fix I.T. Phill has not assessed your WordPress installation, user accounts or files. This guide does not establish that your site is affected, exploited or compromised.

Which Versions Need Attention?

The CNA identifies UsersWP versions through 1.2.70 as affected. The official WordPress.org changelog lists the matching arbitrary file-deletion security correction in 1.2.71, dated August 17, 2026. It also lists 1.2.72, dated August 18. Plan a vendor-supported update that includes the 1.2.71 correction and is compatible with your installation and add-ons; do not choose a package solely because its version number is higher.

The CNA publication on September 11, 2026 is later than those vendor changelog dates. It is not evidence that the fix was released today. The CNA rates the issue High, with a CVSS score of 8.1. An authenticated, low-privileged account is a prerequisite; the reviewed record does not require another user’s interaction.

Confirm the Plugin and Account Scope

  • Confirm that the installed product is UsersWP, the front-end login, registration, profile and members-directory plugin. Similar membership products are not automatically affected by this advisory.
  • Record the active plugin version, any related UsersWP add-ons and whether the affected functionality is used on this site.
  • Review legitimate registration and account-management workflows. Subscriber accounts are low privilege, but they are still authenticated accounts; do not treat the issue as administrator-only.
  • Use your normal access-review process to investigate unexpected accounts or permissions. Do not assume that every registered user is malicious, or disable customer accounts indiscriminately.

Plan and Validate the Update

  1. Read the official changelog and check compatibility with the site’s WordPress version, theme, UsersWP add-ons and registration integrations.
  2. Confirm that your existing recovery process is available and understood before the maintenance window. This guide does not require creating a full account export or changing backup schedules.
  3. Where an authorized staging environment is already available, validate the supported update there before scheduling the production change.
  4. After updating, confirm the installed version in WordPress and test normal registration, login, profile editing, password recovery and membership-directory workflows with authorized test accounts.
  5. Check that expected site files and legitimate user content remain available. Use normal administrative monitoring; do not run attack simulations against production to prove that an update worked.

WordPress update timing and package availability can vary. Our plugin auto-update cooling-period guide provides related maintenance context. Do not weaken security controls or obtain an unofficial package to work around a delayed update.

Keep Patching Separate From Recovery

Installing a patched plugin alone does not establish that earlier unauthorized changes or deletions have been resolved. If normal monitoring reveals unexpected missing files, account activity or site behavior, preserve relevant evidence privately and use your incident-response and recovery process. Do not include passwords, customer details or private logs in public support requests.

The sources reviewed for this guide do not establish exploitation on your site. An absent CISA KEV listing is not proof that exploitation cannot occur.

Get Help With a Controlled Maintenance Window

For version assessment, compatibility review and post-update checks, use WordPress support. Review related security maintenance guides when planning changes across more than one component.

Image context: the featured illustration depicts general server maintenance. It is not a UsersWP interface, a customer system or proof that an update has been completed.

Primary Sources