Vulnerability index

Browse CVEs

22 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Front End Users CRITICAL 9.8
CVE-2025-47580

Missing Authorization vulnerability in Rustaurius Front End Users front-end-only-users allows Exploiting Incorrectly Configured Access Control Securi…

Fix: after 3.2.32
Fix from $2,300 2025-05-15
Front End Users HIGH 7.1
CVE-2024-13569

The Front End Users WordPress plugin through 3.2.32 does not sanitise and escape a parameter before outputting it back in the page, leading to a Refl…

Fix: after 3.2.32
Fix from $1,950 2025-04-22
Front End Users CRITICAL 9.8
CVE-2025-2005EPSS 20%

The Front End Users plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the file uploads field of the…

Fix: after 3.2.32
Fix from $2,300 2025-04-02
Front End Users MEDIUM 5.4
CVE-2025-26877

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Rustaurius Front End Users front-end-only-users…

Fix: 3.2.31+
Fix from $1,600 2025-02-25
Front End Users MEDIUM 5.4
CVE-2024-13563

The Front End Users plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's forgot-password shortcode in all versions up t…

Fix: 3.2.31+
Fix from $1,600 2025-02-15
Order Tracking HIGH 8.8
CVE-2024-43343

Missing Authorization vulnerability in Etoile Web Design Order Tracking allows Accessing Functionality Not Properly Constrained by ACLs.This issue af…

Fix: 3.3.13+
Fix from $1,950 2024-11-01
Front End Users HIGH 8.8
CVE-2024-7607

The Front End Users plugin for WordPress is vulnerable to time-based SQL Injection via the ‘order’ parameter in all versions up to, and including, 3.…

Fix: 3.2.29+
Fix from $1,950 2024-08-29
Front End Users MEDIUM 5.4
CVE-2024-7606

The Front End Users plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'user-search' shortcode in all versions up to,…

Fix: 3.2.29+
Fix from $1,600 2024-08-29
Front End Users MEDIUM 6.1
CVE-2023-33322

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Etoile Web Design Front End Users allows Reflec…

Fix: 3.2.25+
Fix from $1,600 2024-03-26
Ultimate Reviews MEDIUM 6.1
CVE-2024-25597

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Etoile Web Design Ultimate Reviews allows Store…

Fix: 3.2.9+
Fix from $1,600 2024-03-15
Order Tracking MEDIUM 6.1
CVE-2023-4471

The Order Tracking Pro plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the start_date and end_date parameters in versions up…

Fix: after 3.3.6
Fix from $1,600 2023-08-31
Front End Users HIGH 8.8
CVE-2023-34005

Cross-Site Request Forgery (CSRF) vulnerability in Etoile Web Design Front End Users plugin <= 3.2.24 versions.

Fix: after 3.2.24
Fix from $1,950 2023-07-17
Ultimate Reviews CRITICAL 9.8
CVE-2020-36726

The Ultimate Reviews plugin for WordPress is vulnerable to PHP Object Injection in versions up to, and including, 2.1.32 via deserialization of untru…

Fix: after 2.1.32
Fix from $2,300 2023-06-07
Ultimate Product Catalog MEDIUM 6.5
CVE-2021-24993

The Ultimate Product Catalog WordPress plugin before 5.0.26 does not have authorisation and CSRF checks in some AJAX actions, which could allow any a…

Fix: 5.0.26+
Fix from $1,600 2022-02-07
Ultimate Faq MEDIUM 5.7
CVE-2021-24968

The Ultimate FAQ WordPress plugin before 2.1.2 does not have capability and CSRF checks in the ewd_ufaq_welcome_add_faq and ewd_ufaq_welcome_add_faq_…

Fix: 2.1.2+
Fix from $1,600 2022-01-24
Ultimate Appointment Booking \& Scheduling MEDIUM 6.1
CVE-2020-24313

Etoile Web Design Ultimate Appointment Booking & Scheduling WordPress Plugin v1.1.9 and lower does not sanitize the value of the "Appointment_ID" GET…

Fix: after 1.1.9
Fix from $1,600 2020-08-26
Ultimate Faq MEDIUM 6.1
CVE-2020-7107

The Ultimate FAQ plugin before 1.8.30 for WordPress allows XSS via Display_FAQ to Shortcodes/DisplayFAQs.php.

Fix: 1.8.30+
Fix from $1,600 2020-01-16
Ultimate Faq HIGH 7.5
CVE-2019-17232

Functions/EWD_UFAQ_Import.php in the ultimate-faqs plugin through 1.8.24 for WordPress allows unauthenticated options import.

Fix: after 1.8.24
Fix from $1,950 2019-10-07
Ultimate Faq MEDIUM 6.1
CVE-2019-17233

Functions/EWD_UFAQ_Import.php in the ultimate-faqs plugin through 1.8.24 for WordPress allows HTML content injection.

Fix: after 1.8.24
Fix from $1,600 2019-10-07
Ultimate Faq MEDIUM 6.1
CVE-2019-15643

The ultimate-faqs plugin before 1.8.22 for WordPress has XSS.

Fix: 1.8.22+
Fix from $1,600 2019-08-27
Ultimate Product Catalog CRITICAL 9.8
CVE-2017-12199

The Etoile Ultimate Product Catalog plugin 4.2.11 for WordPress has SQL injection with these wp-admin/admin-ajax.php POST actions: catalogue_update_o…

No fix yet
Fix from $2,300 2017-08-02
Ultimate Product Catalog MEDIUM 6.1
CVE-2017-12200

The Etoile Ultimate Product Catalog plugin 4.2.11 for WordPress has XSS in the Add Product Manually component.

Mitigation only
Fix from $1,600 2017-08-02