AI description
CVE-2025-2005 affects the Front End Users plugin for WordPress, specifically versions up to and including 3.2.32. The vulnerability stems from a lack of file type validation in the file upload field of the registration form. This missing validation allows unauthenticated attackers to upload arbitrary files to the affected server. These files could include malicious PHP files (web shells), potentially leading to remote code execution and complete compromise of the server.
- Description
- The Front End Users plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the file uploads field of the registration form in all versions up to, and including, 3.2.32. This makes it possible for unauthenticated attackers to upload arbitrary files on the affected site's server which may make remote code execution possible.
- Source
- security@wordfence.com
- NVD status
- Awaiting Analysis
CVSS 3.1
- Type
- Primary
- Base score
- 9.8
- Impact score
- 5.9
- Exploitability score
- 3.9
- Vector string
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
- Severity
- CRITICAL
- security@wordfence.com
- CWE-434
- Hype score
- Not currently trending
CVE-2025-2005 The Front End Users plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the file uploads field of the registration form … https://t.co/CUb5IqtdUC
@CVEnew
2 Apr 2025
264 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
�� CVE-2025-2005 - WordPress - HIGH 🚨 🗓️ Date published 2025-04-02 10:15:19 UTC #WordPress #CyberSecurity #InfoSec #Vulnerability #TechNews https://t.co/sJITnpno5e
@vulns_space
2 Apr 2025
36 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
⚠️⚠️ CVE-2025-2005(CVSS 10): WordPress Front End Users Plugin File Upload, version affected: <=3.2.32 🔥PoC: https://t.co/xq7GAiuc0C 🎯1.3k+ Results are found on the https://t.co/pb16tGYaKe nearly year. 🔗FOFA Link:https://t.co/b8XyhAdtt4 FOFA
@fofabot
2 Apr 2025
2423 Impressions
14 Retweets
43 Likes
26 Bookmarks
0 Replies
0 Quotes