Medium 6.5 Unfixed
2025-09-22≤ 3.2.35
Front End Users <= 3.2.33 - Authenticated (Contributor+) Stored Cross-Site Scripting
Minimum safe version
3.2.34
Update to 3.2.34 or later to address 12 fixable vulnerabilities
Front End Users <= 3.2.33 - Authenticated (Contributor+) Stored Cross-Site Scripting
CVE-2025-62072
WordPress Front End Users plugin <= 3.2.35 - Broken Access Control vulnerability
CVE-2024-13569
Front-End-Only-Users <= 3.2.32 - Unauthenticated Arbitrary File Upload
Front End Users <= 3.2.32 - Authenticated (Admin+) SQL injection
CVE-2025-26877
CVE-2024-13563
CVE-2024-7606
CVE-2024-7607
CVE-2023-34005
CVE-2023-33322
Front End Users <= 3.2.24 - Missing Authorization to Unauthenticated Registered User Deletion
Front End Users <= 3.2.24 - Cross-Site Request Forgery