All verified exploits

CVE-2025-2005 Front End Users Unauthenticated File Upload

Deterministic critical WordPress Added cve-verified-cve-2025-2005

Detects the Front End Users WordPress plugin at version 3.2.32 or earlier, where the registration form file upload field lacks file type validation. An unauthenticated attacker can upload a PHP webshell through the registration form, which is stored in a predictable uploads directory, enabling remote code execution.

Related WordPress exploits

Is your app exploitable through CVE-2025-2005?

Scan your domain free