ThreatPress

WordPress Vulnerability Database

Back

WordPress WP Quick FrontEnd Editor plugin <= 5.5 - Authenticated Settings Change and Stored Cross-Site Scripting (XSS) vulnerability

Product
WP Quick FrontEnd Editor
Description
Authenticated Settings Change and Stored Cross-Site Scripting (XSS) vulnerability found by Jerome Bruandet (NinTechNet) in WordPress WP Quick FrontEnd Editor plugin (versions <= 5.5).
Solution
2021-01-18 - we were unable to find a patched version of this plugin. WordPress.org notification: "This plugin has been closed as of October 23, 2020 and is not available for download. Reason: Security Issue."
Classification
Type Multiple Vulnerabilities
OWASP Top 10 A3: Cross Site Scripting (XSS)
References
Vulnerability details
Plugin changelog
CVE
Name CVE-N/A
Versions
Affected In <= 5.5
Disclosure date
2021-01-12
Credits
Jerome Bruandet (NinTechNet)