Impact
A missing file type validation flaw in the registration form of the Front End Users plugin allows attackers to upload any file type to the web server without authentication. Once an attacker places a malicious file in the upload directory, the file may be executed, giving the attacker remote code execution capabilities. The weakness is classified as CWE‑434, a classic example of uncontrolled upload vulnerability.
Affected Systems
All WordPress sites that have the Front End Users plugin installed at version 3.2.32 or earlier are impacted. Administrators should upgrade the plugin.
Risk and Exploitability
The CVSS score of 9.8 and the EPSS score of 20% show that the flaw is frequently exploited in the wild. Because the upload form is publicly accessible, an unauthenticated attacker can simply POST a crafted request to the registration endpoint. The vulnerability is not listed in the CISA KEV catalog, yet its high severity and exploitation likelihood demand urgent attention.
OpenCVE Enrichment
EUVD