Vulnerabilities (CVE)

Filtered by vendor Wpfront Subscribe
Filtered by product Wpfront User Role Editor
Total 1 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2021-24984 1 Wpfront 1 Wpfront User Role Editor 2024-02-28 4.3 MEDIUM 6.1 MEDIUM
The WPFront User Role Editor WordPress plugin before 3.2.1.11184 does not sanitise and escape the changes-saved parameter before outputting it back in the admin dashboard, leading to a Reflected Cross-Site Scripting