Medium 6.5
2025-09-26< 4.2.4
WPFront User Role Editor <= 4.2.3 - Authenticated (Contributor+) Stored Cross-Site Scripting
Minimum safe version
4.2.4
Update to 4.2.4 or later to address 5 fixable vulnerabilities
WPFront User Role Editor <= 4.2.3 - Authenticated (Contributor+) Stored Cross-Site Scripting
WordPress WPFront User Role Editor Plugin <= 4.2.1 is vulnerable to Cross Site Request Forgery (CSRF)
CVE-2024-2931
WPFront User Role Editor < 3.2.1.11184 - Reflected Cross-Site Scripting
CVE-2021-24984