CVE · Medium

CVE-2024-2931 — WPFront User Role Editor [wpfront-user-role-editor] < 4.1.0

CVE Vulnerability Type Severity Affected Fixed in Published Status
CVE-2024-2931 WPFront User Role Editor [wpfront-user-role-editor] < 4.1.0 Exposure of Sensitive Information to an Unauthorized Actor Medium 4.3 < 4.1.0 4.1.0 2024-04-01

CVE-2024-2931

The WPFront User Role Editor plugin for WordPress contains a sensitive information disclosure flaw affecting versions up to and including 3.2.1.11184 through the wpfront_user_role_editor_assign_roles_user_autocomplete AJAX action. Any authenticated user with at least subscriber-level permissions can exploit this vulnerability to retrieve a complete list of email addresses belonging to all registered site users. This exposure of user contact information affects the privacy of the WordPress installation's user base.

Based on public CVE data (MITRE/NVD).

Scan your WordPress site free

No signup, no credit card — enter your URL and get a security report in seconds.