Cross-Site Request Forgery (CSRF) vulnerability in Stiofan UsersWP userswp allows Cross Site Request Forgery.This issue affects UsersWP: from n/a through <= 1.2.53.
We have discovered 1,700 live websites that are affected by CVE-2026-25015.
| Product | |
| Category | Wordpress Plugins |
| Vulnerable Domains | 1,700 live websites (50% of Userswp install base) |
| Vulnerable Versions |
|
| Vulnerable Versions Count | 86 versions ( 93% of all versions) |
| 578 websites | |
| 161 websites | |
| 119 websites | |
| 112 websites | |
| 63 websites | |
| 49 websites | |
| 47 websites | |
| 42 websites | |
| 41 websites | |
| 38 websites |
| .com | 692 websites |
| .org | 146 websites |
| .de | 82 websites |
| .it | 77 websites |
| .co.uk | 66 websites |
| .net | 50 websites |
| .com.au | 31 websites |
| .ru | 31 websites |
| .ca | 27 websites |
| .pl | 27 websites |
| Domain | Country | Rank | Contacts |
|---|---|---|---|
| ***************.org | *,*** | ||
| **********.id | **,*** | ||
| *********.com | **,*** | ||
| ************************.de | **,*** | ||
| ********.com | ***,*** | ||
| *****.*******.io | ***,*** | ||
| **.today | ***,*** | ||
| ******.com | ***,*** | ||
| ************.com | ***,*** | ||
| *****.org | ***,*** |