PT-2026-50637 · Stiofansisland · Userswp – Front-End Login Form

Pasindu Dilshan

·

Published

2026-06-18

·

Updated

2026-06-18

·

CVE-2026-12102

CVSS v3.1

2.7

Low

VectorAV:N/AC:L/PR:H/UI:N/S:U/C:N/I:L/A:N
The UsersWP – Front-end login form, User Registration, User Profile & Members Directory plugin for WP plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 1.2.63 via the 'user id' parameter due to missing validation on a user controlled key. This makes it possible for authenticated attackers, with editor-level access and above, to reset and permanently delete the avatar or banner image of any arbitrary user, including administrators, by clearing their avatar thumb or banner thumb metadata in the uwp usermeta table.

Fix

IDOR

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-12102

Affected Products

Userswp – Front-End Login Form