CVE-2024-2931: WPFront User Role Editor <= 3.2.1.11184 - Limited Information Exposure
The WPFront User Role Editor plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 3.2.1.11184 via the wpfrontuserroleeditorassignrolesuserautocomplete AJAX action. This makes it possible for authenticated attackers, with subscriber-level access and above, to extract retrieve a list of all user email addresses who are registered on the site.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-2931?
CVE-2024-2931 has been classified as a medium severity vulnerability.
How do I fix CVE-2024-2931?
To mitigate CVE-2024-2931, update the WPFront User Role Editor plugin to version 3.2.1.11185 or later.
Who is affected by CVE-2024-2931?
CVE-2024-2931 affects users of the WPFront User Role Editor plugin for WordPress in all versions up to and including 3.2.1.11184.
What type of vulnerability is CVE-2024-2931?
CVE-2024-2931 is a sensitivity information exposure vulnerability.
Can CVE-2024-2931 be exploited by unauthenticated users?
No, CVE-2024-2931 can only be exploited by authenticated users with subscriber-level access.