PT-2025-17486 · WordPress · Front End Users

Published

2025-04-22

·

Updated

2026-02-12

·

CVE-2024-13569

CVSS v3.1

7.1

High

VectorAV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L
Name of the Vulnerable Software and Affected Versions Front End Users WordPress plugin versions 3.2.32 and earlier
Description The issue is related to a Reflected Cross-Site Scripting problem, where the Front End Users WordPress plugin does not properly sanitise and escape a parameter before outputting it back in the page. This could be used against high privilege users such as admin.
Recommendations For versions 3.2.32 and earlier, update to a version that properly sanitises and escapes parameters to prevent Reflected Cross-Site Scripting. As a temporary workaround, consider restricting access to the plugin's functionality to minimize the risk of exploitation.

Exploit

Fix

XSS

Weakness Enumeration

Related Identifiers

CVE-2024-13569

Affected Products

Front End Users