Wpfront User Role Editor
Vendor:
First CVE: Dec 27, 2021 · Active for 4 years
2
Total CVEs
More Total CVEs than 49% of tracked products
1.0
Avg CVEs / Year
Bottom 1%
5.2
Avg CVSS
Higher Avg CVSS than 9% of tracked products
0.0%
KEV Rate
Bottom 1%
Trends Over Time
The number and severity of CVEs published that impact Wpfront User Role Editor over time
Volume of CVEsAvg CVSS Base Score
First CVE
Dec 27, 2021
4 years ago
Most Recent CVE
Apr 2, 2024
844 days ago
CVE Severity & Scoring
Wpfront User Role Editor2 CVEs
100%
All CVEs352,708 CVEs
45%
40%
11%
Medium
Attack Vector
Local0 (0.0%)
Network2 (100.0%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low2 (100.0%)
High0 (0.0%)
Unknown0 (0.0%)
User Interaction
None1 (50.0%)
Unknown0 (0.0%)
Required1 (50.0%)
Privileges Required
Low1 (50.0%)
High0 (0.0%)
None1 (50.0%)
Unknown0 (0.0%)
Top CVEs
Signals from CVEs in this product scope (2 CVEs).
2 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2021-24984MEDIUM The WPFront User Role Editor WordPress plugin before 3.2.1.11184 does not sanitise and escape the changes-saved parameter before outputting it back in the admin dashboard, leading | Dec 27, 2021 | 6.1 | 22 | NO | NO |
CVE-2024-2931MEDIUM The WPFront User Role Editor plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 3.2.1.11184 via the wpfront_user_role_editor | Apr 2, 2024 | 4.3 | 15 | NO | NO |
Exploit Exposure
Signals from CVEs in this product scope (2 CVEs).
CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%
Social Chatter
Signals from CVEs in this product scope (2 CVEs).
Media Mentions
Signals from CVEs in this product scope (2 CVEs).
Top CNAs Publishing CVEs For Wpfront User Role Editor
Top CWEs
Versions
No cataloged versions.