WPFront User Role Editor
WPFront User Role Editor has 5 disclosed vulnerabilities in the WordSec catalog, reported between 2021 and 2025; all 5 are fixed as of September 2026. Their average CVSS score is 6.3, and the most serious one scores 8.8 out of 10. Severity breakdown: 0 critical and 1 high. 2025 was the busiest year with 2 disclosures.
The most common weakness is Cross-Site Scripting, behind 3 of the records (60%). Other recurring categories include Cross-Site Request Forgery (CSRF), Exposure Of Sensitive Information To An Unauthorized Actor.
Every one of the 5 issues recorded for WPFront User Role Editor has a vendor fix available, so running the current release closes all known holes.
4 independent researchers contributed these findings, most of them (2) reported by ZhongFu Su. WPFront User Role Editor is installed on roughly 30,000 WordPress sites, so each unpatched flaw has a wide blast radius. The current release is tested up to WordPress 7.1.
CVE-2025-3064WPFront User Role Editor <= 4.2.1 - Cross-Site Request Forgery to Privilege Escalation via whitelist_options Function
Read the full analysisVulnerability Records

WPFront User Role Editor
Author
Syam Mohan
WPFront User Role Editor plugin allows you to easily manage WordPress user roles within your site. You can create, edit or delete user roles and manage role capabilities. Features Create new roles. Edit or rename existing roles. Clone existing roles. Manage capabilities. Allows you to add role capabilities. Change default user role. Add or Remove capabilities. Restore role. Assign multiple roles. Migrate users. Navigation menu permissions basic. Widget permissions basic. Login redirect basic. Admin menu editor. [PRO] Media library permissions. [PRO] User level permissions. [PRO] Navigation menu permissions advanced. [PRO] Widget permissions advanced. [PRO] Login redirect advanced. [PRO] Post/Page extended permissions. [PRO] Custom post type permissions. [PRO] Content restriction shortcodes. [PRO] Import/Export. [PRO] Multisite support. [PRO] Compare User Role Editor Pro Spanish tutorial
Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C