AyeCode UsersWP
cpe:2.3:a:ayecode:userswp:*:*:*:*:wordpress:*:*
- <= 1.2.44
A time-based SQL injection vulnerability has been identified in the UsersWP plugin for WordPress, specifically in the front-end login form, user registration, user profile, and members directory features. This vulnerability affects all versions through 1.2.44. The issue arises in the 'upload_file_remove' function, where insufficient escaping of user-supplied data in the 'htmlvar' parameter allows unauthenticated attackers to inject additional SQL queries. Exploitation of this vulnerability could lead to the extraction of sensitive information from the database.
Exploitation of this vulnerability could allow an attacker to manipulate SQL queries, potentially leading to unauthorized access to sensitive database information.
Users are advised to update the UsersWP plugin to version 1.2.45 or later.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.