CVE-2026-25015 | UsersWP Plugin up to 1.2.53 on WordPress ajax_avatar_banner_upload cross-site request forgery
A vulnerability identified as problematic has been detected in UsersWP Plugin up to 1.2.53 on WordPress. Affected is the function ajax_avatar_banner_upload. Performing a manipulation results in cross-site request forgery.
This vulnerability is reported as CVE-2026-25015. The attack is possible to be carried out remotely. No exploit exists.