VYPR

WP Frontend Profile

by WordPress

CVEs (5)

  • CVE-2023-51483CriMay 17, 2024
    risk 0.64cvss 9.8epss 0.01

    Improper Privilege Management vulnerability in Glowlogix WP Frontend Profile allows Privilege Escalation.This issue affects WP Frontend Profile: from n/a through 1.3.1.

  • CVE-2019-15111CriAug 21, 2019
    risk 0.64cvss 9.8epss 0.02

    The wp-front-end-profile plugin before 0.2.2 for WordPress has a privilege escalation issue.

  • CVE-2019-15110MedAug 21, 2019
    risk 0.40cvss 6.1epss 0.01

    The wp-front-end-profile plugin before 0.2.2 for WordPress has XSS.

  • CVE-2026-39688MedApr 8, 2026
    risk 0.34cvss 5.3epss 0.00

    Missing Authorization vulnerability in Glowlogix WP Frontend Profile wp-front-end-profile allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects WP Frontend Profile: from n/a through <= 1.3.9.

  • CVE-2026-1644MedMar 7, 2026
    risk 0.28cvss 4.3epss 0.00

    The WP Frontend Profile plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.3.8. This is due to missing nonce validation on the 'update_action' function. This makes it possible for unauthenticated attackers to approve or…