WP Delete User Accounts

WP Delete User Accounts has 2 disclosed vulnerabilities in the WordSec catalog, all reported in 2025; 1 is fixed and 1 remains unpatched as of September 2026. Their average CVSS score is 6.4, and the most serious one scores 6.4 out of 10. 2025 was the busiest year with 2 disclosures.

The most common weakness is Cross-Site Scripting, behind 2 of the records (100%).

1 of the records (50%) have a vendor fix, while 1 remain unpatched. The oldest unresolved one dates back to 2025.

All of these findings were reported by Muhammad Yudha - DJ. WP Delete User Accounts is installed on roughly 800 WordPress sites, so each unpatched flaw has a wide blast radius. The current release is tested up to WordPress 6.7.7.

Strategic Overview

Avg CVSSMedium
6.4/ 10
Patch Coverage50%
Open

1

Fixed

1

Get automatic notifications for all WP Delete User Accounts vulnerabilities before they are exploited.

Most severe open issueCVSS 6.4CVE-2025-58704

WP Delete User Accounts <= 1.2.4 - Authenticated (Contributor+) Stored Cross-Site Scripting

Read the full analysis

Vulnerability Records

2 records
Plugin Profile
Latestv1.2.4

WP Delete User Accounts

Ren Ventura

Author

Ren Ventura

4.9(7)
98/100
Last Updated
2025-03-29 (2y ago)
Active Installs
800+
Downloads
19,876
Requires WP
0+
Requires PHP
0+
Tested up to
WP 6.7.7
Created
2016-01-19 (11y ago)

Allow your users (except for administrators) to manually delete their own accounts. It uses the Sweet Alert jQuery plugin for slick-looking alerts and prompts. By default, this plugin adds a button to a user’s profile page in the wp-admin. You can also add a delete button to any page or post using the [wp_delete_user_accounts] shortcode. NOTE: Delete buttons are not displayed when logged in as an administrator. This is done to protect against locking yourself out of your site. To see the delete button, you’ll need to log in with an account that does not have the administrator role. For more technical info, including available hooks (actions and filters), please see the plugin’s readme file on Github.

Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C