Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

Front End Users — Vulnerabilities & Security Advisories 12

All 12 CVE vulnerabilities found in Front End Users, with AI-generated Chinese analysis, references, and POCs.

This page details vulnerability aggregations for the product category classified as Front End Users. It collects reported security weaknesses affecting web-based client applications, browser extensions, and standalone user-facing software interfaces. The data spans from January 1, 2018, through the present date, ensuring a comprehensive view of historical and emerging threats in this domain. Here, users can track specific vendor advisories related to front-end security flaws, understand the characteristics and impact of common weakness classes such as cross-site scripting or insecure direct object references, and look up individual products to review their complete vulnerability history. This aggregation serves as a centralized reference for security researchers, application developers, and system administrators to assess risk exposure associated with client-side technologies. By organizing findings by vendor and product version, the page facilitates rapid identification of patched versus unpatched issues. It supports proactive security management by highlighting trends in front-end attack vectors and enabling informed decision-making regarding software updates and mitigation strategies. The information provided is derived from public security databases and vendor disclosures, offering an unbiased overview of the current threat landscape for end-user applications without speculative commentary or promotional content.

Vendor: Etoile Web Design

CVE ID Title CVSS Severity Published
CVE-2025-62072 WordPress Front End Users plugin <= 3.2.33 - Broken Access Control vulnerability CWE-862 4.3 Medium 2025-10-22
CVE-2025-58235 WordPress Front End Users plugin <= 3.2.35 - Cross Site Scripting (XSS) vulnerability CWE-79 6.5 Medium 2025-09-22
CVE-2025-47580 WordPress Front End Users plugin <= 3.2.35 - Broken Access Control vulnerability CWE-862 5.4 Medium 2025-05-15
CVE-2024-13569 Front End Users <= 3.2.32 - Reflected XSS 6.1 - 2025-04-22
CVE-2024-12410 Front End Users <= 3.2.32 - Authenticated (Admin+) SQL injection CWE-89 4.9 Medium 2025-04-02
CVE-2025-2005 Front-End-Only-Users <= 3.2.32 - Unauthenticated Arbitrary File Upload CWE-434 9.8 Critical 2025-04-02
CVE-2025-26877 WordPress Front End Users Plugin <= 3.2.30 - Cross Site Scripting (XSS) vulnerability CWE-79 6.5 Medium 2025-02-25
CVE-2024-13563 Front End Users <= 3.2.30 - Authenticated (Contributor+) Stored Cross-Site Scripting via forgot-password Shortcode CWE-79 6.4 Medium 2025-02-15
CVE-2024-7607 Front End Users <= 3.2.28 - Authenticated (Contributor+) Time-Based SQL Injection CWE-89 8.8 High 2024-08-29
CVE-2024-7606 Front End Users <= 3.2.28 - Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode CWE-79 6.4 Medium 2024-08-29
CVE-2023-33322 WordPress Front End Users plugin < 3.2.25 - Cross Site Scripting (XSS) vulnerability CWE-79 7.1 High 2024-03-26
CVE-2023-34005 WordPress Front End Users Plugin <= 3.2.24 is vulnerable to Cross Site Request Forgery (CSRF) CWE-352 6.5 Medium 2023-07-17

All 12 known CVE vulnerabilities affecting Front End Users with full Chinese analysis, references, and POCs where available.