WP Frontend Profile <= 1.3.8 - Cross-Site Request Forgery to Unauthorized User Account Approval or Rejection
WP Frontend Profile
Minimum safe version
1.3.9
Update to 1.3.9 or later to address 12 fixable vulnerabilities
CVE-2026-39688
Freemius SDK <= 2.4.2 - Missing Authorization Checks
WordPress WP Frontend Profile Plugin <= 1.3.1 is vulnerable to Privilege Escalation
WP Frontend Profile < 1.2.2 - CSRF Check Incorrectly Implemented
WordPress WP Frontend Profile Plugin <= 1.3.0 is vulnerable to Cross Site Scripting (XSS)
WP Frontend Profile <= 1.2.1 - Cross-Site Request Forgery
Freemius SDK <= 2.4.2 - Missing Authorization Checks
WordPress Front End Profile Plugin <= 0.2.1 - Multiple Vulnerabilities
WordPress WP Frontend Profile plugin <= 1.2.1 - Nonce Security Issue vulnerability
WordPress WP Frontend Profile plugin <= 1.2.5 - Sensitive Information Disclosure vulnerability
WordPress WP Frontend Profile plugin <= 1.2.5 - Toggle The Debug Mode via Cross-Site Request Forgery (CSRF) vulnerability
CVE-2019-15110
CVE-2019-15111