Etoilewebdesign maintains a focused portfolio of web-based e-commerce and content-management plugins and modules, including products such as Ultimate FAQ, Ultimate Product Catalog, and Order Tracking that are embedded across small-to-medium business websites. Despite a narrow product range, this vendor appears prominently in the vulnerability landscape, with disclosures skewing toward critical-severity outcomes and frequently acquiring public exploit code. The recurring weakness classes center on web-application fundamentals: cross-site scripting, SQL injection, missing authorization, cross-site request forgery, and untrusted deserialization—flaws typical of server-side plugins that handle user input and manage access control with minimal isolation. Defenders deploying these plugins should treat security updates as high-priority and audit authentication and input-handling configurations; current exploitation activity and severity counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Etoilewebdesign over time
Signals from CVEs in this vendor scope (26 CVEs).
26 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2025-2005CRITICAL The Front End Users plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the file uploads field of the registration form in all versi | Apr 2, 2025 | 9.8 | 42 | NO | NO |
CVE-2019-17232HIGH Functions/EWD_UFAQ_Import.php in the ultimate-faqs plugin through 1.8.24 for WordPress allows unauthenticated options import. | Oct 7, 2019 | 7.5 | 35 | NO | YES |
CVE-2024-13569HIGH The Front End Users WordPress plugin through 3.2.32 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting whic | Apr 22, 2025 | 7.1 | 30 | NO | YES |
CVE-2019-17233MEDIUM Functions/EWD_UFAQ_Import.php in the ultimate-faqs plugin through 1.8.24 for WordPress allows HTML content injection. | Oct 7, 2019 | 6.1 | 30 | NO | YES |
CVE-2025-47580CRITICAL Missing Authorization vulnerability in Rustaurius Front End Users front-end-only-users allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Fr | May 15, 2025 | 9.8 | 29 | NO | NO |
CVE-2020-36726CRITICAL The Ultimate Reviews plugin for WordPress is vulnerable to PHP Object Injection in versions up to, and including, 2.1.32 via deserialization of untrusted input in several vulnerabl | Jun 7, 2023 | 9.8 | 27 | NO | NO |
CVE-2024-7607HIGH The Front End Users plugin for WordPress is vulnerable to time-based SQL Injection via the ‘order’ parameter in all versions up to, and including, 3.2.28 due to insufficient escapi | Aug 29, 2024 | 8.8 | 25 | NO | NO |
CVE-2020-7107MEDIUM The Ultimate FAQ plugin before 1.8.30 for WordPress allows XSS via Display_FAQ to Shortcodes/DisplayFAQs.php. | Jan 16, 2020 | 6.1 | 25 | NO | YES |
CVE-2023-34005HIGH Cross-Site Request Forgery (CSRF) vulnerability in Etoile Web Design Front End Users plugin <= 3.2.24 versions. | Jul 17, 2023 | 8.8 | 24 | NO | NO |
CVE-2017-12199CRITICAL The Etoile Ultimate Product Catalog plugin 4.2.11 for WordPress has SQL injection with these wp-admin/admin-ajax.php POST actions: catalogue_update_order list-item, video_update_or | Aug 2, 2017 | 9.8 | 24 | NO | NO |
Signals from CVEs in this vendor scope (26 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Etoilewebdesign.
Media articles that mention a CVE ID that affects a product developed by Etoilewebdesign — matched by CVE ID, not by vendor name.