VYPR

Guest posting / Frontend Posting / Front Editor

by Guest posting / Frontend Posting / Front Editor

CVEs (2)

  • CVE-2026-1867MedMar 11, 2026
    risk 0.38cvss 5.9epss 0.00

    The Guest posting / Frontend Posting / Front Editor WordPress plugin before 5.0.6 allows passing a URL parameter to regenerate a .json file based on demo data that it initially creates. If an administrator modifies the demo form and enables admin notifications in the Guest posting / Frontend Posting / Front Editor WordPress plugin before 5.0.6's settings, it is possible for an unauthenticated attacker to export and download all of the form data/settings, including the administrator's email address.

  • CVE-2025-12569MedNov 24, 2025
    risk 0.31cvss 4.7epss 0.00

    The Guest posting / Frontend Posting / Front Editor WordPress plugin before 5.0.0 does not validate a parameter before redirecting the user to its value, leading to an Open Redirect issue