WP Quick FrontEnd Editor <= 5.5 - Authenticated (Subscriber+) Content Injection
Summary
| CVE | CVE-2021-4383 |
|---|---|
| State | PUBLISHED |
| Assigner | Wordfence |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2023-06-07 02:15:15 UTC |
| Updated | 2026-04-08 19:17:43 UTC |
| Description | The WP Quick FrontEnd Editor plugin for WordPress is vulnerable to page content injection in versions up to, and including, 5.5. This is due to missing capability checks in the plugin's page-editing functionality. This makes it possible for low-authenticated attackers, such as subscribers, to edit/create any page or post on the blog. |
Risk And Classification
Primary CVSS: v3.1 4.3 MEDIUM from [email protected]
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N
EPSS: 0.001430000 probability, percentile 0.346550000 (date 2026-04-09)
Problem Types: CWE-862 | CWE-862 CWE-862 Missing Authorization
| Version | Source | Type | Score | Severity | Vector |
|---|---|---|---|---|---|
| 3.1 | [email protected] | Primary | 4.3 | MEDIUM | CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N |
| 3.1 | [email protected] | Secondary | 8.1 | HIGH | CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H |
| 3.1 | CNA | DECLARED | 8.1 | HIGH | CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H |
CVSS v3.1 Breakdown
Attack Vector
NetworkAttack Complexity
LowPrivileges Required
LowUser Interaction
NoneScope
UnchangedConfidentiality
NoneIntegrity
LowAvailability
NoneCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Webdevocean | Wp Quick Frontend Editor | All | All | All | All |
Vendor Declared Affected Products
| Source | Vendor | Product | Version | Platforms |
|---|---|---|---|---|
| CNA | Labibahmed42 | WP Quick FrontEnd Editor WordPress Plugin | affected 5.5 semver | Not specified |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| Multiple vulnerabilities in WordPress WP Quick FrontEnd Editor plugin (unpatched). – NinTechNet | af854a3a-2127-422b-91ae-364da2661108 | blog.nintechnet.com | Exploit |
| WP Quick FrontEnd Editor <= 5.5 - Authenticated (Subscriber+) Content Injection | af854a3a-2127-422b-91ae-364da2661108 | www.wordfence.com | Third Party Advisory |
| WP Quick FrontEnd Editor – WordPress Plugin – WordPress plugin | WordPress.org | af854a3a-2127-422b-91ae-364da2661108 | wordpress.org | Product |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
Vendor Comments And Credit
Discovery Credit
CNA: Jerome Bruandet (en)
Additional Advisory Data
| Source | Time | Event |
|---|---|---|
| CNA | 2021-01-12T00:00:00.000Z | Disclosed |
There are currently no legacy QID mappings associated with this CVE.