CVE-2024-2931: WPFront User Role Editor <= 3.2.1.11184 - Limited Information Exposure

Published Apr 2, 2024
·
Updated

The WPFront User Role Editor plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 3.2.1.11184 via the wpfrontuserroleeditorassignrolesuserautocomplete AJAX action. This makes it possible for authenticated attackers, with subscriber-level access and above, to extract retrieve a list of all user email addresses who are registered on the site.

Affected Software

2 affected components
WPFront User Role Editor<=3.2.1.11184
WPFront WPFront User Role Editor WordPress<4.1.0

Event History

Apr 2, 2024
CVE Published
via MITRE·08:32 AM
Data Sourced
via MITRE·08:32 AM
DescriptionSeverityWeakness
Data Sourced
via NVD·09:15 AM
RemedyDescriptionSeverityWeaknessAffected Software
Apr 7, 58713
Event
via FIRST·04:56 AM

Frequently Asked Questions

1

What is the severity of CVE-2024-2931?

CVE-2024-2931 has been classified as a medium severity vulnerability.

2

How do I fix CVE-2024-2931?

To mitigate CVE-2024-2931, update the WPFront User Role Editor plugin to version 3.2.1.11185 or later.

3

Who is affected by CVE-2024-2931?

CVE-2024-2931 affects users of the WPFront User Role Editor plugin for WordPress in all versions up to and including 3.2.1.11184.

4

What type of vulnerability is CVE-2024-2931?

CVE-2024-2931 is a sensitivity information exposure vulnerability.

5

Can CVE-2024-2931 be exploited by unauthenticated users?

No, CVE-2024-2931 can only be exploited by authenticated users with subscriber-level access.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203