Description
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Rustaurius Front End Users front-end-only-users allows Stored XSS.This issue affects Front End Users: from n/a through <= 3.2.30.
Published: 2025-02-25
Score: 6.5 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

Stored cross‐site scripting arises when unsanitized input is rendered into web pages. The Front End Users plugin contains a flaw that fails to neutralize user‑supplied data displayed on the site, allowing attackers to inject arbitrary JavaScript. If an attacker succeeds, the injected script runs in the context of any visitor's browser, potentially stealing session cookies, defacing content, or executing further actions on behalf of the user.

Affected Systems

The vulnerability impacts WordPress sites that have the Rustaurius Front End Users plugin installed, versions up to and including 3.2.30. Sites running any earlier release or any newer version are considered unimpacted. Site administrators should verify the plugin version and ensure it is not within the affected range.

Risk and Exploitability

The CVSS score of 6.5 reflects the medium severity of a stored XSS that requires a user to visit a crafted page. The EPSS is reported as less than 1%, indicating a very low probability of exploitation in the wild, and the vulnerability is not listed in CISA's KEV catalog. Nonetheless, attackers who find a victim browsing the affected site could easily inject malicious scripts, so the risk remains real for any exposed site. Based on the description, it is inferred that the likely attack vector is through the plugin's front‑end user interface, where user input is accepted and later displayed without proper escaping.

Generated by OpenCVE AI on May 1, 2026 at 15:29 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade the Front End Users plugin to a version newer than 3.2.30; current releases contain the fix.
  • Apply a Content Security Policy that blocks inline scripts and enforces script‑src directives to mitigate any remaining XSS exposure.
  • Sanitize and validate user input through a security plugin or custom code to prevent future injection.

Generated by OpenCVE AI on May 1, 2026 at 15:29 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
EUVD EUVD EUVD-2025-5444 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Rustaurius Front End Users allows Stored XSS. This issue affects Front End Users: from n/a through 3.2.30.
History

Thu, 23 Apr 2026 15:00:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 5.4, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N'}

cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L'}


Wed, 01 Apr 2026 23:45:00 +0000

Type Values Removed Values Added
Description Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Rustaurius Front End Users allows Stored XSS. This issue affects Front End Users: from n/a through 3.2.30. Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Rustaurius Front End Users front-end-only-users allows Stored XSS.This issue affects Front End Users: from n/a through <= 3.2.30.
References
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L'}

cvssV3_1

{'score': 5.4, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N'}


Wed, 09 Jul 2025 15:00:00 +0000

Type Values Removed Values Added
First Time appeared Etoilewebdesign
Etoilewebdesign front End Users
CPEs cpe:2.3:a:etoilewebdesign:front_end_users:*:*:*:*:*:wordpress:*:*
Vendors & Products Etoilewebdesign
Etoilewebdesign front End Users

Tue, 25 Feb 2025 15:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 25 Feb 2025 14:30:00 +0000

Type Values Removed Values Added
Description Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Rustaurius Front End Users allows Stored XSS. This issue affects Front End Users: from n/a through 3.2.30.
Title WordPress Front End Users Plugin <= 3.2.30 - Cross Site Scripting (XSS) vulnerability
Weaknesses CWE-79
References
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L'}


Subscriptions

Etoilewebdesign Front End Users
cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published:

Updated: 2026-04-28T16:11:41.347Z

Reserved: 2025-02-17T11:50:22.448Z

Link: CVE-2025-26877

cve-icon Vulnrichment

Updated: 2025-02-25T14:37:59.287Z

cve-icon NVD

Status : Modified

Published: 2025-02-25T15:15:24.380

Modified: 2026-04-23T15:25:59.103

Link: CVE-2025-26877

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-05-01T15:30:20Z

Weaknesses