VULNERABILITY OVERVIEW The UsersWP – Front-end login form, User Registration, User Profile & Members Directory plugin for WordPress is affected by a blind Server-Side Request Forgery (SSRF) vulnerability in all versions up to and including 1.2.58. The flaw exists in the process_image_crop() method, which improperly validates user-supplied URLs during avatar and banner image crop operations. This vulnerability allows authenticated attackers to manipulate image processing functionality to initiate arbitrary outbound HTTP requests from the vulnerable server. SEVERITY ASSESSMENT This vulnerability carries a CVSS 3.1 score of 5.0 (Medium severity) with a network-based attack vector requiring low complexity and low privileges (subscriber-level access). The attack requires no user interaction and can impact the confidentiality of the compromised system across scope boundaries. The root cause is insufficient URL origin validation—the code relies only on esc_url() sanitization and file type verification, failing to enforce that URLs reference legitimate local upload files. PHP image processing functions used downstream support URL wrappers, enabling the server to make unauthorized requests to attacker-controlled or internal network destinations, potentially exposing sensitive internal services. EXPLOITATION STATUS There is no evidence of active exploitation, with no entries on the Known Exploited Vulnerabilities (KEV) catalog and an EPSS score of 0.0001 indicating minimal real-world exploitation probability. The vulnerability remains on the community radar with a Faucet Risk Score of 40.0/100, warranting attention but not representing an immediate critical threat. Organizations using affected versions should prioritize patching to versions beyond 1.2.58 to remediate this risk.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
| Stiofansisland | UsersWP – Front-End Login Form, User Registration, User Profile & Members Directory Plugin For WP | >= 0, <= 1.2.58CNA affecteddefault unaffected |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:N/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.