MEDIUM
Glowlogix
CVE published 2026-04-08
CVE-2026-39688
A Missing Authorization vulnerability was discovered in WP Frontend Profile, a WordPress plugin. The issue, tracked as CVE-2026-39688, allows attackers to exploit incorrectly configured access control security levels. The vulnerability affects WP Frontend Profile versions from n/a through 1.3.9. Administrators and users should review plugin configurations and update to a secure version if available.