CVE-2026-25015
Description
Cross-Site Request Forgery (CSRF) vulnerability in Stiofan UsersWP userswp allows Cross Site Request Forgery.This issue affects UsersWP: from n/a through <= 1.2.53.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
UsersWP plugin <=1.2.53 for WordPress contains a CSRF vulnerability that could allow attackers to force privileged users to execute unintended actions.
Vulnerability
Overview
The UsersWP plugin for WordPress versions from n/a through 1.2.53 contains a Cross-Site Request Forgery (CSRF) vulnerability [1]. This type of vulnerability allows an attacker to trick an authenticated user into performing actions they did not intend to take, by crafting a malicious link or form that the victim unknowingly submits while authenticated [1].
Exploitation
Requirements
To exploit this CSRF vulnerability, the attacker must convince a privileged user (such as an administrator) to interact with a crafted link, visit a malicious page, or submit a specially designed form [1]. No authentication is required for the attacker, but the victim must have an active session with the vulnerable WordPress site [1].
Impact
Successful exploitation could allow a malicious actor to force the higher-privileged user to execute unwanted actions under their current authentication state [1]. This could lead to unauthorized changes to the site's configuration, user data, or other administrative functions, depending on the specific actions the vulnerable plugin exposes.
Mitigation
The vulnerability has been addressed in version 1.2.54 of the UsersWP plugin [1]. Users are strongly advised to update to this version or later immediately to mitigate the risk [1]. The vendor recommends using auto-updates for vulnerable plugins, and users who cannot update should contact their hosting provider or web developer for assistance [1].
AI Insight generated on May 19, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.
Affected products
2Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
1News mentions
1- Wordfence Intelligence Weekly WordPress Vulnerability Report (April 6, 2026 to April 12, 2026)Wordfence Blog · Apr 16, 2026