PT-2026-107829 · WordPress · Frontend Dashboard
CVSS v3.1
9.8
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Frontend Dashboard versions prior to 3.0.5
Description
This issue occurs because the plugin fails to perform authorization or nonce checks on actions available to unauthenticated users. This allows an attacker to call an arbitrary PHP function or class method using request data, which can lead to the takeover of any account, including those with administrator privileges. A nonce is a unique token used to protect against cross-site request forgery (CSRF) by ensuring that a request was intentionally sent by the user.
Recommendations
Update to version 3.0.5 or later.
Exploit
Fix
Improper Privilege Management
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Frontend Dashboard