CVE-2025-2005: Front-End-Only-Users <= 3.2.32 - Unauthenticated Arbitrary File Upload
The Front End Users plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the file uploads field of the registration form in all versions up to, and including, 3.2.32. This makes it possible for unauthenticated attackers to upload arbitrary files on the affected site's server which may make remote code execution possible.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-2005?
CVE-2025-2005 has a high severity rating due to the potential for unauthenticated arbitrary file uploads.
How do I fix CVE-2025-2005?
To fix CVE-2025-2005, update the WordPress Front End Users plugin to version 3.2.33 or higher.
Who is affected by CVE-2025-2005?
All users of the WordPress Front End Users plugin up to and including version 3.2.32 are affected by CVE-2025-2005.
What type of vulnerability is CVE-2025-2005?
CVE-2025-2005 is an arbitrary file upload vulnerability caused by missing file type validation.
Can CVE-2025-2005 be exploited by authenticated users?
No, CVE-2025-2005 can be exploited by unauthenticated users, making it particularly dangerous.