Filtered by vendor Wpfront
                         Subscriptions
                    
                    
                
                        Filtered by product Wpfront User Role Editor
                         Subscriptions
                    
                    
                
                    Total
                    3 CVE
                
            | CVE | Vendors | Products | Updated | CVSS v3.1 | 
|---|---|---|---|---|
| CVE-2025-60102 | 2 Wordpress, Wpfront | 2 Wordpress, Wpfront User Role Editor | 2025-09-29 | 6.5 Medium | 
| Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Syam Mohan WPFront User Role Editor allows Stored XSS. This issue affects WPFront User Role Editor: from n/a through 4.2.3. | ||||
| CVE-2024-2931 | 1 Wpfront | 1 Wpfront User Role Editor | 2025-08-28 | 4.3 Medium | 
| The WPFront User Role Editor plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 3.2.1.11184 via the wpfront_user_role_editor_assign_roles_user_autocomplete AJAX action. This makes it possible for authenticated attackers, with subscriber-level access and above, to extract retrieve a list of all user email addresses who are registered on the site. | ||||
| CVE-2021-24984 | 1 Wpfront | 1 Wpfront User Role Editor | 2024-11-21 | 6.1 Medium | 
| The WPFront User Role Editor WordPress plugin before 3.2.1.11184 does not sanitise and escape the changes-saved parameter before outputting it back in the admin dashboard, leading to a Reflected Cross-Site Scripting | ||||
                            
                                
                                
                                    Page 1 of 1.
                                
                                
                            
                        
                     ReportizFlow
ReportizFlow