The UsersWP – Front-end login form, User Registration, User Profile & Members Directory plugin for WP plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'uwp_profile' and 'uwp_profile_header' shortcodes in all versions up to, and including, 1.2.42 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.
We have discovered 1,011 live websites that are affected by CVE-2025-9344.
| Product | |
| Category | Wordpress Plugins |
| Vulnerable Domains | 1,011 live websites (29% of Userswp install base) |
| Vulnerable Versions |
|
| Vulnerable Versions Count | 76 versions ( 83% of all versions) |
| 322 websites | |
| 95 websites | |
| 74 websites | |
| 67 websites | |
| 44 websites | |
| 36 websites | |
| 35 websites | |
| 28 websites | |
| 25 websites | |
| 22 websites |
| .com | 390 websites |
| .org | 84 websites |
| .it | 51 websites |
| .de | 45 websites |
| .co.uk | 35 websites |
| .net | 31 websites |
| .ru | 28 websites |
| .pl | 23 websites |
| .fr | 19 websites |
| .ca | 17 websites |
| Domain | Country | Rank | Contacts |
|---|---|---|---|
| ***************.org | *,*** | ||
| *********.com | **,*** | ||
| ********.com | ***,*** | ||
| **.today | ***,*** | ||
| ******.com | ***,*** | ||
| ************.com | ***,*** | ||
| *****.org | ***,*** | ||
| **********.org | ***,*** | ||
| ******.com | ***,*** | ||
| *****************.ca | ***,*** |
FAQ