PT-2025-49967 · WordPress · Userswp

Published

2025-12-09

·

Updated

2025-12-15

·

CVE-2025-67593

CVSS v3.1

4.3

Medium

VectorAV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N
Name of the Vulnerable Software and Affected Versions UsersWP versions through 1.2.48
Description The UsersWP plugin contains a Cross-Site Request Forgery (CSRF) flaw. This allows attackers to potentially perform actions on behalf of an authenticated user without their knowledge. The issue impacts the UsersWP plugin.
Recommendations Update UsersWP to a version later than 1.2.48.

Fix

CSRF

Weakness Enumeration

Related Identifiers

CVE-2025-67593

Affected Products

Userswp