Access Control Flaw in UsersWP by Stiofan Can Lead to Unauthorized Access
CVE-2025-66072
4.3MEDIUM
What is CVE-2025-66072?
A missing authorization vulnerability in the UsersWP plugin developed by Stiofan allows attackers to exploit incorrectly configured access control security levels. This vulnerability can lead to unauthorized access, enabling malicious actors to perform actions that should be restricted. UsersWP versions up to and including 1.2.47 are affected, which can compromise user data and system integrity if not addressed.
Affected Version(s)
UsersWP <= n/a