Executive brief
WP Frontend Profile is a WordPress plugin that allows users to manage their profiles from the front-end of a website. A security flaw in the plugin's access control settings could allow unauthorized individuals to bypass intended security levels. This could lead to unauthorized access to profile information or minor service disruptions, though it is currently considered a low-priority threat.
Technical details
A missing authorization vulnerability (CWE-862) exists in the Glowlogix WP Frontend Profile plugin through version 1.3.9. The flaw stems from incorrectly configured access control security levels within the wp-front-end-profile component. An unauthenticated remote attacker can exploit this lack of authorization checks to perform actions or access data that should be restricted to higher-privileged users. While the CVSS score is 5.3 (Medium), the impact is primarily limited to partial information disclosure or minor availability issues. As of the advisory date, no official patch has been released.
Affected products
- Glowlogix WP Frontend Profile <= 1.3.9
Timeline
- 2026-01-24: other: Vulnerability reported by Legion Hunter
- 2026-02-23: disclosed: Initial disclosure by Patchstack
- 2026-04-08: advisory: CVE published to NVD