VYPR

Vendor CVEs

Etoilewebdesign

All CVEs

26 total · sorted by risk
  • CVE-2025-2005CriApr 2, 2025
    risk 0.65cvss 9.8epss 0.20

    The Front End Users plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the file uploads field of the registration form in all versions up to, and including, 3.2.32. This makes it possible for unauthenticated attackers to upload…

  • CVE-2020-36726CriJun 7, 2023
    risk 0.64cvss 9.8epss 0.02

    The Ultimate Reviews plugin for WordPress is vulnerable to PHP Object Injection in versions up to, and including, 2.1.32 via deserialization of untrusted input in several vulnerable functions. This allows unauthenticated attackers to inject a PHP Object. No POP chain is present…

  • CVE-2017-12199CriAug 2, 2017
    risk 0.64cvss 9.8epss 0.02

    The Etoile Ultimate Product Catalog plugin 4.2.11 for WordPress has SQL injection with these wp-admin/admin-ajax.php POST actions: catalogue_update_order list-item, video_update_order video-item, image_update_order list-item, tag_group_update_order list_item,…

  • CVE-2024-7607HigAug 29, 2024
    risk 0.57cvss 8.8epss 0.01

    The Front End Users plugin for WordPress is vulnerable to time-based SQL Injection via the ‘order’ parameter in all versions up to, and including, 3.2.28 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query.…

  • CVE-2019-17232HigOct 7, 2019
    risk 0.49cvss 7.5epss 0.04

    Functions/EWD_UFAQ_Import.php in the ultimate-faqs plugin through 1.8.24 for WordPress allows unauthenticated options import.

  • CVE-2024-13569HigApr 22, 2025
    risk 0.46cvss 7.1epss 0.01

    The Front End Users WordPress plugin through 3.2.32 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin.

  • CVE-2023-33322HigMar 26, 2024
    risk 0.46cvss 7.1epss 0.00

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Etoile Web Design Front End Users allows Reflected XSS.This issue affects Front End Users: from n/a before 3.2.25.

  • CVE-2024-25597HigMar 15, 2024
    risk 0.46cvss 7.1epss 0.00

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Etoile Web Design Ultimate Reviews allows Stored XSS.This issue affects Ultimate Reviews: from n/a through 3.2.8.

  • CVE-2025-26877MedFeb 25, 2025
    risk 0.42cvss 6.5epss 0.00

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Rustaurius Front End Users front-end-only-users allows Stored XSS.This issue affects Front End Users: from n/a through <= 3.2.30.

  • CVE-2023-34005MedJul 17, 2023
    risk 0.42cvss 6.5epss 0.00

    Cross-Site Request Forgery (CSRF) vulnerability in Etoile Web Design Front End Users plugin <= 3.2.24 versions.

  • CVE-2023-4471MedAug 31, 2023
    risk 0.40cvss 6.1epss 0.00

    The Order Tracking Pro plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the start_date and end_date parameters in versions up to, and including, 3.3.6 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated…

  • CVE-2020-24313MedAug 26, 2020
    risk 0.40cvss 6.1epss 0.01

    Etoile Web Design Ultimate Appointment Booking & Scheduling WordPress Plugin v1.1.9 and lower does not sanitize the value of the "Appointment_ID" GET parameter before echoing it back out inside an input tag. This results in a reflected XSS vulnerability that attackers can…

  • CVE-2020-7107MedJan 16, 2020
    risk 0.40cvss 6.1epss 0.02

    The Ultimate FAQ plugin before 1.8.30 for WordPress allows XSS via Display_FAQ to Shortcodes/DisplayFAQs.php.

  • CVE-2019-17233MedOct 7, 2019
    risk 0.40cvss 6.1epss 0.02

    Functions/EWD_UFAQ_Import.php in the ultimate-faqs plugin through 1.8.24 for WordPress allows HTML content injection.

  • CVE-2019-15643MedAug 27, 2019
    risk 0.40cvss 6.1epss 0.01

    The ultimate-faqs plugin before 1.8.22 for WordPress has XSS.

  • CVE-2017-12200MedAug 2, 2017
    risk 0.40cvss 6.1epss 0.01

    The Etoile Ultimate Product Catalog plugin 4.2.11 for WordPress has XSS in the Add Product Manually component.

  • CVE-2025-47580MedMay 15, 2025
    risk 0.35cvss 5.4epss 0.00

    Missing Authorization vulnerability in Rustaurius Front End Users front-end-only-users allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Front End Users: from n/a through <= 3.2.35.

  • CVE-2024-13563MedFeb 15, 2025
    risk 0.35cvss 6.4epss 0.00

    The Front End Users plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's forgot-password shortcode in all versions up to, and including, 3.2.30 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it…

  • CVE-2024-7606MedAug 29, 2024
    risk 0.35cvss 6.4epss 0.00

    The Front End Users plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'user-search' shortcode in all versions up to, and including, 3.2.28 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it…

  • CVE-2021-24993MedFeb 7, 2022
    risk 0.35cvss 6.5epss 0.00

    The Ultimate Product Catalog WordPress plugin before 5.0.26 does not have authorisation and CSRF checks in some AJAX actions, which could allow any authenticated users, such as subscriber to call them and add arbitrary products, or change the plugin's settings for example

  • CVE-2024-12410MedApr 2, 2025
    risk 0.32cvss 4.9epss 0.00

    The Front End Users plugin for WordPress is vulnerable to SQL Injection via the 'UserSearchField' parameter in all versions up to, and including, 3.2.32 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. …

  • CVE-2023-4500MedAug 31, 2023
    risk 0.31cvss 4.7epss 0.00

    The Order Tracking Pro plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the order status parameter in versions up to, and including, 3.3.6 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers (admin…

  • CVE-2023-2711MedJun 27, 2023
    risk 0.31cvss 4.8epss 0.01

    The Ultimate Product Catalog WordPress plugin before 5.2.6 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example…

  • CVE-2022-23979MedJan 28, 2022
    risk 0.31cvss 4.8epss 0.01

    Authenticated (admin+) Stored Cross-Site Scripting (XSS) vulnerability discovered in Ultimate Reviews WordPress plugin (versions <= 3.0.15).

  • CVE-2021-24968MedJan 24, 2022
    risk 0.30cvss 5.7epss 0.00

    The Ultimate FAQ WordPress plugin before 2.1.2 does not have capability and CSRF checks in the ewd_ufaq_welcome_add_faq and ewd_ufaq_welcome_add_faq_page AJAX actions, available to any authenticated users. As a result, any users, with a role as low as Subscriber could create FAQ…

  • CVE-2024-43343MedNov 1, 2024
    risk 0.28cvss 4.3epss 0.00

    Missing Authorization vulnerability in Etoile Web Design Order Tracking allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects Order Tracking: from n/a through 3.3.12.