WordPress Plugin Vulnerabilities

Frontend Dashboard 3.0.0 - 3.0.4 - Unauthenticated Privilege Escalation via Arbitrary Function Call

Description

The plugin does not perform any authorisation or nonce check on actions available to unauthenticated users that call an attacker-chosen PHP function or class method with the request data, allowing unauthenticated users to take over any account, including administrators.

Proof of Concept

Affects Plugins

Fixed in 3.0.5

References

Classification

Miscellaneous

Original Researcher
Ryan Fabella
Submitter
Ryan Fabella
Verified
Yes

Timeline

Publicly Published
2026-10-06 (about 2 days ago)
Added
2026-10-06 (about 1 day ago)
Last Updated
2026-10-07 (about 8 hours ago)

Other