Authenticated Settings Change and Stored Cross-Site Scripting (XSS) vulnerability found by Jerome Bruandet (NinTechNet) in WordPress WP Quick FrontEnd Editor plugin (versions <= 5.5).
Solution
2021-01-18 - we were unable to find a patched version of this plugin.
WordPress.org notification: "This plugin has been closed as of October 23, 2020 and is not available for download. Reason: Security Issue."
Classification
Type Multiple Vulnerabilities OWASP Top 10 A3: Cross Site Scripting (XSS)