What is CVE-2026-18501?
This vulnerability affects all versions of the “UsersWP” plugin for WordPress up to and including 1.2.69. A Stored Cross-Site Scripting flaw exists via “Badge Widget Variable Substitution” due to insufficient input sanitization and output escaping. Updating the plugin to the latest version is recommended.
Azərbaycanca: Bu boşluq WordPress-in “UsersWP” plaqininin 1.2.69 versiyasına qədər olan bütün versiyalarına təsir edir. “Badge Widget Variable Substitution” vasitəsilə Stored Cross-Site Scripting (Saxlanılmış Saytlararası Skriptləşdirmə) zəifliyi mövcuddur ki, bu da yetərsiz giriş təmizləməsi və çıxış kodlamasından qaynaqlanır. Plaqini son versiyaya yeniləmək tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-79
FAQ2
Which WordPress plugin is affected by CVE-2026-18501?
This vulnerability affects the “UsersWP” plugin for WordPress.
What measure is recommended to protect against this Stored XSS vulnerability?
Updating the plugin to the latest version is recommended.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.