CVE-2025-2005
largeUnauthenticated Arbitrary File Upload in WordPress Front End Users Plugin
CVE-2025-2005 is an arbitrary file upload flaw in the Front End Users WordPress plugin by Etoile Web Design, caused by missing file type validation on the file uploads field of the registration form. An unauthenticated attacker can reach the registration form over the network and upload arbitrary files to the affected site's server without any user interaction or privileges. Because uploaded content is not type-checked, an attacker may be able to place executable files (such as PHP scripts) on the server, potentially achieving remote code execution with full confidentiality, integrity, and availability impact. Any WordPress site running Front End Users version 3.2.32 or earlier is affected. No public proof-of-concept or confirmed in-the-wild exploitation is known yet, but the 22% EPSS probability of exploitation within 30 days (98th percentile) indicates an elevated near-term threat.
What to do: Update Front End Users to the latest patched release (any version after 3.2.32) as soon as possible. Until updated, restrict or disable the file upload field on the registration form and consider a WAF rule blocking unauthenticated file uploads to registration endpoints; also check the site's uploads directory for unexpected PHP or script files that would indicate compromise. If no patched version is available in your environment, deactivate the plugin until an update is released.
| etoilewebdesign Front End Users (WordPress plugin) | All versions up to and including 3.2.32 |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
The Front End Users plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the file uploads field of the registration form in all versions up to, and including, 3.2.32. This makes it possible for unauthenticated attackers to upload arbitrary files on the affected site's server which may make remote code execution possible.
- Vendors
- etoilewebdesign
- Products
- front end users
- Ecosystems
- WordPress
- Weakness
- CWE-434
- Vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
In the news0 stories
No ingested article mentions this CVE yet.