
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2025-53444 is a Cross-Site Request Forgery (CSRF) vulnerability in the DeluxeThemes Userpro WordPress plugin affecting all versions before 5.1.11. It allows unauthenticated remote attackers to perform unauthorized actions on behalf of authenticated users by tricking them into interacting with a crafted request. The vulnerability was reported by Ananda Dhakal of Patchstack on May 13, 2024, and publicly disclosed on April 15, 2026. It carries a CVSS v3.1 base score of 4.3 (Medium) (Patchstack, GitHub Advisory).
The vulnerability is classified as CWE-352 (Cross-Site Request Forgery), meaning the Userpro plugin fails to sufficiently verify whether state-changing requests were intentionally submitted by the authenticated user. An attacker can craft a malicious web page or link that, when visited by a logged-in user, silently submits a forged HTTP request to the WordPress site carrying the victim's session credentials. No privileges are required on the attacker's part, but user interaction (e.g., clicking a link or visiting a crafted page) is necessary for exploitation. The attack vector is network-based with low complexity (Patchstack, GitHub Advisory).
Successful exploitation allows an attacker to force a higher-privileged authenticated user to execute unintended actions within the Userpro plugin without their knowledge or consent, such as modifying user settings or account information. The impact is limited to integrity — there is no confidentiality or availability impact. The vulnerability does not enable direct data exfiltration or system compromise, but unauthorized modifications to user profiles or plugin configuration could facilitate further abuse (Patchstack).
There is no known public proof-of-concept exploit and no evidence of active in-the-wild exploitation at this time (GitHub Advisory). The EPSS score is approximately 0.014% (0.000140), placing it in the 4th percentile for exploitation likelihood within the next 30 days. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. Patchstack rates the exploitation priority as Low, noting the issue is unlikely to be exploited (Patchstack).
wp-admin/admin-ajax.php or Userpro-specific action URLs) from unusual referrer origins or with no referrer header.Referer header, which may indicate a cross-origin forged submission.Update the Userpro plugin to version 5.1.11 or later, which contains the fix for this CSRF vulnerability (Patchstack). Patchstack users can enable auto-update for vulnerable plugins to receive protection automatically. As a general hardening measure, ensure that WordPress security plugins enforcing CSRF token validation are in place, and review access logs for any suspicious form submissions to Userpro endpoints.
The vulnerability was discovered and reported by Ananda Dhakal of Patchstack through their Active Vulnerability Disclosure Program (VDP), with an early warning sent to Patchstack customers on April 15, 2026, the same day it was publicly published (Patchstack). No significant broader media coverage or notable researcher commentary beyond the Patchstack disclosure has been identified.
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."