The Guest posting / Frontend Posting / Front Editor ...
Moderate severity
Unreviewed
Published
Mar 11, 2026
to the GitHub Advisory Database
•
Updated Mar 11, 2026
Description
Published by the National Vulnerability Database
Mar 11, 2026
Published to the GitHub Advisory Database
Mar 11, 2026
Last updated
Mar 11, 2026
The Guest posting / Frontend Posting / Front Editor WordPress plugin before 5.0.6 allows passing a URL parameter to regenerate a .json file based on demo data that it initially creates. If an administrator modifies the demo form and enables admin notifications in the Guest posting / Frontend Posting / Front Editor WordPress plugin before 5.0.6's settings, it is possible for an unauthenticated attacker to export and download all of the form data/settings, including the administrator's email address.
References