CVE-2026-4977 | stiofansisland UsersWP Plugin up to 1.2.58 on WordPress AJAX upload_file_remove htmlvar authorization
A vulnerability, which was classified as critical, has been found in stiofansisland UsersWP Plugin up to 1.2.58 on WordPress. Affected is the function upload_file_remove of the component AJAX Handler. This manipulation of the argument htmlvar causes missing authorization.
This vulnerability is tracked as CVE-2026-4977. The attack is possible to be carried out remotely. No exploit exists.
It is advisable to upgrade the affected component.