WordPress Plugin Vulnerabilities

Frontend Dashboard < 3.0.0 - Subscriber+ Profile and Post Field Deletion via fed_user_profile_delete

Description

The plugin does not perform a capability check in one of its AJAX actions, allowing authenticated users with low privileges, such as subscribers, to delete the plugin's configured profile and post form fields.

Proof of Concept

Affects Plugins

Fixed in 3.0.0

References

Classification

Type
ACCESS CONTROLS
CWE

Miscellaneous

Original Researcher
Daniel Dhaniswara
Submitter
Daniel Dhaniswara
Verified
Yes

Timeline

Publicly Published
2026-10-05 (about 2 days ago)
Added
2026-10-05 (about 1 day ago)
Last Updated
2026-10-05 (about 1 day ago)

Other