UsersWP – Front-end login form, User Registration, User Profile & Members Directory plugin for WordPress, CVE-2026-25015
- CVE, Research URL
- Published on
- Feb 03, 2026
- Research Description
- Cross-Site Request Forgery (CSRF) vulnerability in Stiofan UsersWP userswp allows Cross Site Request Forgery.This issue affects UsersWP: from n/a through <= 1.2.53.
- Affected versions
-
max 1.2.53.
- Status
-
vulnerable