WP Frontend Profile
WP Frontend Profile has 8 disclosed vulnerabilities in the WordSec catalog, reported between 2016 and 2026; 6 are fixed and 2 remain unpatched as of September 2026. Their average CVSS score is 7.1, and the most serious one scores 9.8 out of 10. Severity breakdown: 2 critical and 1 high. 2026 was the busiest year with 2 disclosures.
The most common weakness is Missing Authorization, behind 3 of the records (38%). Other recurring categories include Cross-Site Request Forgery (CSRF), Cross-Site Scripting.
6 of the records (75%) have a vendor fix, while 2 remain unpatched. The oldest unresolved one dates back to 2023.
5 independent researchers contributed these findings, most of them (2) reported by Phil Wylie (mustardbees). WP Frontend Profile is installed on roughly 100 WordPress sites, so each unpatched flaw has a wide blast radius. The current release is tested up to WordPress 6.8.8.
CVE-2023-33999Freemius SDK <= 2.5.9 - Reflected Cross-Site Scripting via fs_request_get
Read the full analysisVulnerability Records

WP Frontend Profile
Author
Glowlogix
WP Frontend Profile gives you the ability to add a extensible user profile section to the frontend of your WordPress website. By default the plugin adds two tabs to the frontend profile. One of these tabs, titled profile, allows a user to edit their user data including email, first and last names, URL and bio (description). The password tab allows a user to change their password for the site. Plugin Extensibility As the frontend profile is rendered with tabs you can easily add your own tabs with your own fields to store user meta data. Tabs and fields are added through filters and all the saving of the data is taken care of for you. You can add the following field types: WYSIWYG Select Multi Select Radio Text Area Checkbox Password Email Text See FAQs for how to add our own fields and tabs. Profile Output To output the frontend profile feature you can use the following shortcodes in editor: Profile page [wpfep-profile] Edit profile [wpfep] Register page [wpfep-register] Login page [wpfep-login] Features Added Login Widget Addon for Mailchimp Added Content Restriction feature for paid members.
Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C