wpfront records
6 published records for vendor wpfront.
Researcher profile
- Entered KEV
- 0 · 0%
- Weaponized
- 0 · 0%
- Pre-auth RCE
- 0
- With a fix record
- 0%
- Median publish → KEV
- No record has entered KEV
Recurring classes
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')5
- CWE-200 Exposure of Sensitive Information to an Unauthorized Actor1
The weakness classes this vendor ships most often: where to look.
CWEAttack profile
All records
6 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
24Monitor | CVE-2021-24984No exploit | WPFront User Role Editor < 3.2.1.11184 - Reflected Cross-Site Scriptingwpfront · wpfront user role editor · CWE-79 | Medium6.1 | — | 0.8% | Dec 27, 2021 |
21Monitor | CVE-2021-24601No exploit | WPFront Notification Bar < 2.1.0.08087 - Authenticated Stored XSSwpfront · wpfront notification bar · CWE-79 | Medium5.4 | — | 0.6% | Sep 6, 2021 |
21Monitor | CVE-2021-24564No exploit | WPFront Scroll Top < 2.0.6.07225 - Authenticated Stored XSSwpfront · scroll top · CWE-79 | Medium5.4 | — | 0.6% | Aug 23, 2021 |
19Monitor | CVE-2021-24518No exploit | WPFront Notification Bar < 2.0.0.07176 - Authenticated Stored XSSwpfront · notification bar · CWE-79 | Medium4.8 | — | 0.7% | Aug 16, 2021 |
19Monitor | CVE-2024-0625No exploit | WPFront Notification Bar <= 3.3.2 - Authenticated (Admin+) Stored Cross-Site Scripting via wpfront-notification-bar-options[custom_class]wpfront · wpfront notification bar · CWE-79 | Medium4.8 | — | 0.4% | Jan 24, 2024 |
17Monitor | CVE-2024-2931No exploit | WPFront User Role Editor <= 3.2.1.11184 - Limited Information Exposurewpfront · wpfront user role editor · CWE-200 | Medium4.3 | — | 0.5% | Apr 2, 2024 |
- CVE-2021-2498424Monitor
WPFront User Role Editor < 3.2.1.11184 - Reflected Cross-Site Scripting
MediumCVSS 6.1No exploitEPSS 1%wpfront · wpfront user role editorDec 27, 2021
- CVE-2021-2460121Monitor
WPFront Notification Bar < 2.1.0.08087 - Authenticated Stored XSS
MediumCVSS 5.4No exploitEPSS 1%wpfront · wpfront notification barSep 6, 2021
- CVE-2021-2456421Monitor
WPFront Scroll Top < 2.0.6.07225 - Authenticated Stored XSS
MediumCVSS 5.4No exploitEPSS 1%wpfront · scroll topAug 23, 2021
- CVE-2021-2451819Monitor
WPFront Notification Bar < 2.0.0.07176 - Authenticated Stored XSS
MediumCVSS 4.8No exploitEPSS 1%wpfront · notification barAug 16, 2021
- CVE-2024-062519Monitor
WPFront Notification Bar <= 3.3.2 - Authenticated (Admin+) Stored Cross-Site Scripting via wpfront-notification-bar-options[custom_class]
MediumCVSS 4.8No exploitEPSS 0%wpfront · wpfront notification barJan 24, 2024
- CVE-2024-293117Monitor
WPFront User Role Editor <= 3.2.1.11184 - Limited Information Exposure
MediumCVSS 4.3No exploitEPSS 1%wpfront · wpfront user role editorApr 2, 2024