CVE-2026-4979 - UsersWP <= 1.2.58 - Authenticated (Subscriber+) Server-Side Request Forgery via 'uwp_crop' Parameter
CVE ID :CVE-2026-4979
Published : April 11, 2026, 2:16 a.m. | 13 hours, 57 minutes ago
Description :The UsersWP – Front-end login form, User Registration, User Profile & Members Directory pl...
Related Vulnerabilities
- CVE-2026-5144: The BuddyPress Groupblog plugin for WordPress is vulnerable to Privilege Escalation in all versions HIGH
- CVE-2026-35669: OpenClaw before 2026.3.25 contains a privilege escalation vulnerability in gateway-authenticated plu HIGH
- CVE-2026-3498: The BlockArt Blocks plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'clien MEDIUM
- CVE-2026-32930: Chamilo LMS is a learning management system. Prior to 1.11.38 and 2.0.0-RC.3, an Insecure Direct Obj HIGH
- CVE-2026-40151: PraisonAI is a multi-agent teams system. Prior to 4.5.128, the AgentOS deployment platform exposes a MEDIUM
Related Coverage
Threat Actors