
WP Delete User Accounts Security & Risk Analysis
wordpress.org/plugins/wp-delete-user-accountsAllow your users (except for administrators) to manually delete their own accounts.
Is WP Delete User Accounts Safe to Use in 2026?
Use With Caution
Score 69/100WP Delete User Accounts has 1 unpatched vulnerability. Evaluate alternatives or apply available mitigations.
The "wp-delete-user-accounts" plugin version 1.2.4 exhibits a mixed security posture. On the positive side, static analysis indicates good development practices with all SQL queries using prepared statements, all output being properly escaped, and the presence of nonce and capability checks on its entry points. There are no detected dangerous functions, file operations, or external HTTP requests, and the attack surface through AJAX and shortcodes appears to be protected by authentication checks.
However, the plugin's vulnerability history is a significant concern. With a total of two known CVEs, one of which remains unpatched, and both being of medium severity related to Cross-Site Scripting (XSS), this indicates a recurring pattern of input sanitization or output escaping issues. The fact that a vulnerability was recently discovered (2025-09-22) and is still unpatched suggests a potential for exploitation.
In conclusion, while the current code analysis reveals a solid adherence to secure coding principles for the analyzed version, the historical context of unpatched vulnerabilities, particularly XSS, poses a considerable risk. Users of this plugin should be aware of the past security incidents and the implications of an unpatched vulnerability, even if the immediate code analysis appears clean.
Key Concerns
- Unpatched CVE exists
- History of medium severity XSS vulnerabilities
WP Delete User Accounts Security Vulnerabilities
CVEs by Year
Severity Breakdown
2 total CVEs
WP Delete User Accounts <= 1.2.4 - Authenticated (Contributor+) Stored Cross-Site Scripting
WP Delete User Accounts <= 1.2.3 - Authenticated (Contributor+) Stored Cross-Site Scripting
WP Delete User Accounts Code Analysis
Output Escaping
WP Delete User Accounts Attack Surface
AJAX Handlers 1
Shortcodes 1
WordPress Hooks 4
Maintenance & Trust
WP Delete User Accounts Maintenance & Trust
Maintenance Signals
Community Trust
WP Delete User Accounts Alternatives
User Social Profiles
user-social-profiles
Plugin adds social fields to user profile in admin panel (Dashboard > Users).
Social Accounts
social-accounts
Add a new section under Settings for your social accounts. The order and the images can be customized with ease.
Simple Social Icons
simple-social-icons
This plugin provides two ways to display social icons: a traditional widget (available on all WordPress versions) and block variations for the core So …
Lightweight Social Icons
lightweight-social-icons
Looking to add simple social icons to your widget areas? Choose the size and color of your icons, and then choose from 47 different social profiles.
Allow Multiple Accounts
allow-multiple-accounts
Allow multiple user accounts to be created, registered, and updated having the same email address.
WP Delete User Accounts Developer Profile
6 plugins · 2K total installs
How We Detect WP Delete User Accounts
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/wp-delete-user-accounts/assets/css/wp-delete-user-accounts.css/wp-content/plugins/wp-delete-user-accounts/assets/js/sweetalert.min.js/wp-content/plugins/wp-delete-user-accounts/assets/js/wp-delete-user-accounts.js/wp-content/plugins/wp-delete-user-accounts/assets/js/sweetalert.min.js/wp-content/plugins/wp-delete-user-accounts/assets/js/wp-delete-user-accounts.jswp-delete-user-accounts/assets/css/wp-delete-user-accounts.css?ver=wp-delete-user-accounts/assets/js/sweetalert.min.js?ver=wp-delete-user-accounts/assets/js/wp-delete-user-accounts.js?ver=HTML / DOM Fingerprints
wp_delete_user_accounts_js[wp_delete_user_accounts]