CVE-2025-66072: WordPress UsersWP plugin <= 1.2.47 - Broken Access Control vulnerability
Missing Authorization vulnerability in Stiofan UsersWP userswp allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects UsersWP: from n/a through <= 1.2.47.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-66072?
CVE-2025-66072 is classified as a missing authorization vulnerability that can lead to unauthorized access due to incorrectly configured access control security levels.
How do I fix CVE-2025-66072?
To fix CVE-2025-66072, update the UsersWP plugin to a version higher than 1.2.47 to ensure correct access control configurations.
What versions are affected by CVE-2025-66072?
CVE-2025-66072 affects UsersWP versions up to and including 1.2.47.
What types of attacks can CVE-2025-66072 enable?
CVE-2025-66072 can potentially enable unauthorized users to gain access to sensitive areas of the application or user data due to improper access controls.
Who is impacted by CVE-2025-66072?
Users of the UsersWP plugin for WordPress using version 1.2.47 or earlier are impacted by CVE-2025-66072.