PT-2026-50637 · Stiofansisland · Userswp – Front-End Login Form

Pasindu Dilshan

·

Publicado

2026-06-18

·

Atualizado

2026-06-18

·

CVE-2026-12102

CVSS v3.1

2.7

Baixa

VetorAV:N/AC:L/PR:H/UI:N/S:U/C:N/I:L/A:N
The UsersWP – Front-end login form, User Registration, User Profile & Members Directory plugin for WP plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 1.2.63 via the 'user id' parameter due to missing validation on a user controlled key. This makes it possible for authenticated attackers, with editor-level access and above, to reset and permanently delete the avatar or banner image of any arbitrary user, including administrators, by clearing their avatar thumb or banner thumb metadata in the uwp usermeta table.

Correção

IDOR

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2026-12102

Produtos afetados

Userswp – Front-End Login Form