CVE-2025-66072

WordPress UsersWP plugin <= 1.2.47 - Broken Access Control vulnerability

Missing Authorization vulnerability in Stiofan UsersWP userswp allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects UsersWP: from n/a through <= 1.2.47.


We have discovered 1,264 live websites that are affected by CVE-2025-66072.

Run a Free Instant Scan




Affected Software

Product  Userswp
Category Wordpress Plugins
Vulnerable Domains1,264 live websites (37% of Userswp install base)
Vulnerable Versions
  • from 0 through 1.2.47
Vulnerable Versions Count80 versions ( 87% of all versions)



Details

  • Published - Nov 21, 2025
  • Updated - Apr 1, 2026

Credits

  • Legion Hunter | Patchstack Bug Bounty Program (finder)

Website Distribution by Country

Number of websites using CVE-2025-66072
United States425 websites



Germany119 websites
Italy93 websites
GB79 websites
France53 websites
Spain38 websites
Russia37 websites
Australia33 websites
Poland30 websites
India28 websites

Website Distribution by TLD

Number of websites using CVE-2025-66072
.com504 websites
.org110 websites
.it63 websites
.de57 websites
.co.uk42 websites
.net40 websites
.ru30 websites
.pl25 websites
.fr22 websites
.com.au21 websites

Vulnerable Versions

Vulnerable versions are highlighted in red

Websites affected by CVE-2025-66072

Top websites that are affected by CVE-2025-66072. Please click on the "Contact us" link to get more information.
DomainCountryRankContacts
***************.org United States*,***
*********.com United States**,***
********.com United States***,***
**.today United States***,***
******.com United States***,***
************.com United States***,***
*****.org United States***,***
******.org Germany***,***
**********.org United States***,***
******.com Cyprus***,***
See full domain list

FAQ

A total of 1,264 websites have been identified as vulnerable to CVE-2025-66072, based on global website indexing conducted by WebTechSurvey.
The Userswp is affected by the CVE-2025-66072 vulnerability.
Userswp versions up to and including 1.2.47 are vulnerable to CVE-2025-66072.