WP Delete User Accounts
WP Delete User Accounts has 2 disclosed vulnerabilities in the WordSec catalog, all reported in 2025; 1 is fixed and 1 remains unpatched as of September 2026. Their average CVSS score is 6.4, and the most serious one scores 6.4 out of 10. 2025 was the busiest year with 2 disclosures.
The most common weakness is Cross-Site Scripting, behind 2 of the records (100%).
1 of the records (50%) have a vendor fix, while 1 remain unpatched. The oldest unresolved one dates back to 2025.
All of these findings were reported by Muhammad Yudha - DJ. WP Delete User Accounts is installed on roughly 800 WordPress sites, so each unpatched flaw has a wide blast radius. The current release is tested up to WordPress 6.7.7.
CVE-2025-58704WP Delete User Accounts <= 1.2.4 - Authenticated (Contributor+) Stored Cross-Site Scripting
Read the full analysisVulnerability Records
WP Delete User Accounts
Author
Ren Ventura
Allow your users (except for administrators) to manually delete their own accounts. It uses the Sweet Alert jQuery plugin for slick-looking alerts and prompts. By default, this plugin adds a button to a user’s profile page in the wp-admin. You can also add a delete button to any page or post using the [wp_delete_user_accounts] shortcode. NOTE: Delete buttons are not displayed when logged in as an administrator. This is done to protect against locking yourself out of your site. To see the delete button, you’ll need to log in with an account that does not have the administrator role. For more technical info, including available hooks (actions and filters), please see the plugin’s readme file on Github.
Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C