Extension WordPress
Vulnérabilités WPFront User Role Editor
Cette page rassemble les failles publiées pour WPFront User Role Editor, leurs plages de versions affectées et les correctifs signalés dans la base locale.
Historique de sécurité
CVE et vulnérabilités de WPFront User Role Editor
5 fiches
WPFront User Role Editor <= 4.2.3 – Authenticated (Contributor+) Stored Cross-Site Scripting
The WPFront User Role Editor plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 4.2.3 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level…
*-4.2.3
4.2.4
26/09/2025
WPFront User Role Editor <= 4.2.1 – Cross-Site Request Forgery to Privilege Escalation via whitelist_options Function
The WPFront User Role Editor plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 4.2.1. This is due to missing or incorrect nonce validation on the whitelist_options() function. This makes it…
*-4.2.1
4.2.2
07/04/2025
WPFront User Role Editor <= 3.2.1.11184 – Limited Information Exposure
The WPFront User Role Editor plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 3.2.1.11184 via the wpfront_user_role_editor_assign_roles_user_autocomplete AJAX action. This makes it possible for authenticated attackers, with subscriber-level access and…
*-3.2.1.11184
4.1.0
01/04/2024
WPFront User Role Editor <= 3.2.0 – Reflected Cross-Site Scripting
The WPFront User Role Editor WordPress plugin before 3.2.1 does not sanitise and escape the changes-saved parameter before outputting it back in the admin dashboard, leading to a Reflected Cross-Site Scripting
*-3.2.0
3.2.1
23/11/2021
WPFront User Role Editor < 3.2.1.11184 – Reflected Cross-Site Scripting
The WPFront User Role Editor plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘changes-saved’ parameter in versions before 3.2.1.11184 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to…
[*, 3.2.1.11184)
3.2.1.11184
23/11/2021
Extensions également surveillés
WP Commander
Rechercher dans toute la base WordPress
Utilisez la recherche globale pour retrouver une extension, un thème, une CVE ou un identifiant de vulnérabilité.