Wpfront develops WordPress plugins including user role management and notification bar functionality that extend permissions and interface capabilities across WordPress installations. Its vulnerability profile centers on application-layer input-handling weaknesses, particularly cross-site scripting flaws in page-generation contexts and exposure of sensitive information, typical of third-party plugin development where input sanitization boundaries can be diffuse. Live severity, exploitation status, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Wpfront over time
Signals from CVEs in this vendor scope (6 CVEs).
6 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2021-24984MEDIUM The WPFront User Role Editor WordPress plugin before 3.2.1.11184 does not sanitise and escape the changes-saved parameter before outputting it back in the admin dashboard, leading | Dec 27, 2021 | 6.1 | 22 | NO | NO |
CVE-2021-24518MEDIUM The WPFront Notification Bar WordPress plugin before 2.0.0.07176 does not sanitise or escape its Custom CSS setting, allowing high privilege users such as admin to set XSS payload | Aug 16, 2021 | 4.8 | 20 | NO | NO |
CVE-2021-24601MEDIUM The WPFront Notification Bar WordPress plugin before 2.1.0.08087 does not properly sanitise and escape its settings, which could allow high privilege users to perform Cross-Site Sc | Sep 6, 2021 | 5.4 | 19 | NO | NO |
CVE-2021-24564MEDIUM The WPFront Scroll Top WordPress plugin before 2.0.6.07225 does not sanitise or escape its Image ALT setting before outputting it attributes, leading to an Authenticated Stored Cro | Aug 23, 2021 | 5.4 | 18 | NO | NO |
CVE-2024-0625MEDIUM The WPFront Notification Bar plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘wpfront-notification-bar-options[custom_class]’ parameter in all versions up | Jan 25, 2024 | 4.8 | 17 | NO | NO |
CVE-2024-2931MEDIUM The WPFront User Role Editor plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 3.2.1.11184 via the wpfront_user_role_editor | Apr 2, 2024 | 4.3 | 15 | NO | NO |
Signals from CVEs in this vendor scope (6 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Wpfront.
Media articles that mention a CVE ID that affects a product developed by Wpfront — matched by CVE ID, not by vendor name.