CVE-2024-2931
The WPFront User Role Editor plugin for WordPress contains a sensitive information disclosure flaw affecting versions up to and including 3.2.1.11184 through the wpfront_user_role_editor_assign_roles_user_autocomplete AJAX action. Any authenticated user with at least subscriber-level permissions can exploit this vulnerability to retrieve a complete list of email addresses belonging to all registered site users. This exposure of user contact information affects the privacy of the WordPress installation's user base.
Based on public CVE data (MITRE/NVD).