PT-2026-107829 · WordPress · Frontend Dashboard

·

CVE-2026-103692

·

Published

2026-10-08

·

Updated

2026-10-08

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Frontend Dashboard versions prior to 3.0.5
Description This issue occurs because the plugin fails to perform authorization or nonce checks on actions available to unauthenticated users. This allows an attacker to call an arbitrary PHP function or class method using request data, which can lead to the takeover of any account, including those with administrator privileges. A nonce is a unique token used to protect against cross-site request forgery (CSRF) by ensuring that a request was intentionally sent by the user.
Recommendations Update to version 3.0.5 or later.

Exploit

Fix

Improper Privilege Management

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-103692

Affected Products

Frontend Dashboard