CVE-2025-67593

WordPress UsersWP plugin <= 1.2.48 - Cross Site Request Forgery (CSRF) vulnerability

Cross-Site Request Forgery (CSRF) vulnerability in Stiofan UsersWP userswp allows Cross Site Request Forgery.This issue affects UsersWP: from n/a through <= 1.2.48.


We have discovered 1,328 live websites that are affected by CVE-2025-67593.

Run a Free Instant Scan




Affected Software

Product  Userswp
Category Wordpress Plugins
Vulnerable Domains1,328 live websites (39% of Userswp install base)
Vulnerable Versions
  • from 0 through 1.2.48
Vulnerable Versions Count81 versions ( 88% of all versions)



Details

  • Published - Dec 9, 2025
  • Updated - Apr 1, 2026

Credits

  • daroo | Patchstack Bug Bounty Program (finder)

Website Distribution by Country

Number of websites using CVE-2025-67593
United States452 websites



Germany123 websites
Italy97 websites
GB84 websites
France53 websites
Russia38 websites
Spain38 websites
Australia34 websites
Poland30 websites
South Africa29 websites

Website Distribution by TLD

Number of websites using CVE-2025-67593
.com533 websites
.org116 websites
.it67 websites
.de59 websites
.co.uk45 websites
.net40 websites
.ru31 websites
.pl25 websites
.fr22 websites
.ca21 websites

Vulnerable Versions

Vulnerable versions are highlighted in red

Websites affected by CVE-2025-67593

Top websites that are affected by CVE-2025-67593. Please click on the "Contact us" link to get more information.
DomainCountryRankContacts
***************.org United States*,***
*********.com United States**,***
********.com United States***,***
**.today United States***,***
******.com United States***,***
************.com United States***,***
*****.org United States***,***
*********.com United States***,***
******.org Germany***,***
**********.org United States***,***
See full domain list

FAQ

A total of 1,328 websites have been identified as vulnerable to CVE-2025-67593, based on global website indexing conducted by WebTechSurvey.
The Userswp is affected by the CVE-2025-67593 vulnerability.
Userswp versions up to and including 1.2.48 are vulnerable to CVE-2025-67593.