Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Wpfront

First CVE: Aug 16, 2021Active for: 5 yearsTotal CVEs: 6

Wpfront develops WordPress plugins including user role management and notification bar functionality that extend permissions and interface capabilities across WordPress installations. Its vulnerability profile centers on application-layer input-handling weaknesses, particularly cross-site scripting flaws in page-generation contexts and exposure of sensitive information, typical of third-party plugin development where input sanitization boundaries can be diffuse. Live severity, exploitation status, and exposure counts are shown alongside this summary.

FAUCET AI Generated
6
Total CVEs
More Total CVEs than 86% of tracked vendors
0.8
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 10% of tracked vendors
5.1
Avg CVSS Score
Higher Avg CVSS Score than 14% of tracked vendors
0.0%
In CISA KEV
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact products developed by Wpfront over time

Volume of CVEsAvg CVSS Base Score
First CVE
Aug 16, 2021
4 years ago
Most Recent CVE
Apr 2, 2024
844 days ago

Products(4 total)

Top CVEs

Signals from CVEs in this vendor scope (6 CVEs).

6 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2021-24984MEDIUM
The WPFront User Role Editor WordPress plugin before 3.2.1.11184 does not sanitise and escape the changes-saved parameter before outputting it back in the admin dashboard, leading
Dec 27, 20216.122NONO
CVE-2021-24518MEDIUM
The WPFront Notification Bar WordPress plugin before 2.0.0.07176 does not sanitise or escape its Custom CSS setting, allowing high privilege users such as admin to set XSS payload
Aug 16, 20214.820NONO
CVE-2021-24601MEDIUM
The WPFront Notification Bar WordPress plugin before 2.1.0.08087 does not properly sanitise and escape its settings, which could allow high privilege users to perform Cross-Site Sc
Sep 6, 20215.419NONO
CVE-2021-24564MEDIUM
The WPFront Scroll Top WordPress plugin before 2.0.6.07225 does not sanitise or escape its Image ALT setting before outputting it attributes, leading to an Authenticated Stored Cro
Aug 23, 20215.418NONO
CVE-2024-0625MEDIUM
The WPFront Notification Bar plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘wpfront-notification-bar-options[custom_class]’ parameter in all versions up
Jan 25, 20244.817NONO
CVE-2024-2931MEDIUM
The WPFront User Role Editor plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 3.2.1.11184 via the wpfront_user_role_editor
Apr 2, 20244.315NONO
View all 6 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products6 CVEs
100%
Severity distribution among all CVEs352,708 CVEs
45%
40%
11%
Medium
Attack Vector
Local0 (0.0%)
Network6 (100.0%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low6 (100.0%)
High0 (0.0%)
Unknown0 (0.0%)
User Interaction
None1 (16.7%)
Unknown0 (0.0%)
Required5 (83.3%)
Privileges Required
Low3 (50.0%)
High2 (33.3%)
None1 (16.7%)
Unknown0 (0.0%)

Exploit Exposure

Signals from CVEs in this vendor scope (6 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Wpfront.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Wpfront — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Wpfront's Products

View all 2 CNAs →

Top CWEs