Front-end Editor
Front-end Editor has one disclosed vulnerability in the WordSec catalog, all reported in 2012; it is fixed as of September 2026. Their average CVSS score is 9.8, and the most serious one scores 9.8 out of 10. Severity breakdown: 1 critical and 0 high.
The most common weakness is Unrestricted Upload Of File With Dangerous Type, behind 1 of the records (100%).
The one issue recorded for Front-end Editor has a vendor fix available, so running the current release closes it.
All of these findings were reported by Sammy Forgit. Front-end Editor is installed on roughly 500 WordPress sites, so each unpatched flaw has a wide blast radius. The current release is tested up to WordPress 3.6.1.
CVE-2012-10019Front-end Editor < 2.3 - Arbitrary File Upload
Read the full analysisVulnerability Records
Front-end Editor
Author
scribu
Front-end Editor is a plugin that lets you make changes to your content directly from your site. No need to load the admin backend just to correct a typo. It makes the same capability checks, so that if a user isn’t allowed to edit something in wp-admin, they aren’t allowed to edit it in the front-end either. You can edit posts, pages, custom post types, comments, widgets and many more elements. Goals: save as many trips to the backend as possible compatible with any theme, out of the box light and fast Support and development: Support is handled by the lovely designsimply. I am not developing the plugin anymore; only applying the patches that other people send via Github. Credits: Aloha Editor for the fantastic WYSIWYG editing component Links: Documentation | Plugin News | Author’s Site
Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C