Missing Authorization vulnerability in Stiofan UsersWP userswp allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects UsersWP: from n/a through <= 1.2.47.
We have discovered 1,264 live websites that are affected by CVE-2025-66072.
| Product | |
| Category | Wordpress Plugins |
| Vulnerable Domains | 1,264 live websites (37% of Userswp install base) |
| Vulnerable Versions |
|
| Vulnerable Versions Count | 80 versions ( 87% of all versions) |
| 425 websites | |
| 119 websites | |
| 93 websites | |
| 79 websites | |
| 53 websites | |
| 38 websites | |
| 37 websites | |
| 33 websites | |
| 30 websites | |
| 28 websites |
| .com | 504 websites |
| .org | 110 websites |
| .it | 63 websites |
| .de | 57 websites |
| .co.uk | 42 websites |
| .net | 40 websites |
| .ru | 30 websites |
| .pl | 25 websites |
| .fr | 22 websites |
| .com.au | 21 websites |
| Domain | Country | Rank | Contacts |
|---|---|---|---|
| ***************.org | *,*** | ||
| *********.com | **,*** | ||
| ********.com | ***,*** | ||
| **.today | ***,*** | ||
| ******.com | ***,*** | ||
| ************.com | ***,*** | ||
| *****.org | ***,*** | ||
| ******.org | ***,*** | ||
| **********.org | ***,*** | ||
| ******.com | ***,*** |