Guest posting / Frontend Posting / Front Editor – WP Front User Submit < 5.0.6 - Unauthenticated Information Exposure
Guest posting / Frontend Posting / Front Editor – WP Front User Submit
Minimum safe version
5.0.6
Update to 5.0.6 or later to address 15 fixable vulnerabilities
CVE-2025-13419
CVE-2025-12569
CVE-2025-28988
WordPress WP Front User Submit / Front Editor plugin <= 5.0.6 - Cross Site Request Forgery (CSRF) vulnerability
WordPress WP Front User Submit / Front Editor plugin <= 5.0.6 - Cross Site Scripting (XSS) vulnerability
Freemius SDK <= 2.4.2 - Missing Authorization Checks
CVE-2024-2967
CVE-2023-1982
WordPress WP Front User Submit / Front Editor Plugin <= 4.0.0 is vulnerable to Cross Site Scripting (XSS)
WordPress WP Front User Submit / Front Editor Plugin <= 3.8.4 is vulnerable to Cross Site Scripting (XSS)
Front User Submit | Front Editor <= 3.8.4 - Authenticated (Subscriber+) Stored Cross-Site Scripting
WordPress WP Front User Submit / Front Editor Plugin < 3.8.0 is vulnerable to Cross Site Scripting (XSS)
Front User Submit | Front Editor <= 3.7.0 - Authenticated (Subscriber+) Stored Cross-Site Scripting
Freemius SDK <= 2.4.2 - Missing Authorization Checks
WordPress Guest posting / Frontend Posting wordpress plugin – WP Front User Submit / Front Editor plugin <= 3.4.0 - Sensitive Information Disclosure vulnerability
WordPress Guest posting / Frontend Posting wordpress plugin – WP Front User Submit / Front Editor plugin <= 3.4.0 - Toggle The Debug Mode via Cross-Site Request Forgery (CSRF) vulnerability