Track vulnerabilities like this one. Sign up free to get alerted when software you use is affected.
9.8

CVE-2026-103692: Frontend Dashboard plugin lets anyone hijack admin accounts

CVE-2026-103692 · published 2 days ago
Summary

The Frontend Dashboard WordPress plugin versions 3.0.0 through 3.0.4 let people who are not logged in run any code on your site, which can give them control of any user account, including administrators. This happens because the plugin does not check who is making the request. Update the plugin to version 3.0.5 or later, or remove it, to stop the risk.

What to do
  • Update unknown frontend dashboard to version 3.0.5 or later.
Affected software
VendorProductAffected versions
unknown frontend dashboard < 3.0.5
Original advisory text
Frontend Dashboard 3.0.0 - 3.0.4 - Unauthenticated Privilege Escalation via Arbitrary Function Call
The Frontend Dashboard WordPress plugin before 3.0.5 does not perform any authorisation or nonce check on actions available to unauthenticated users that call an attacker-chosen PHP function or class method with the request data, allowing unauthenticated users to take over any account, including administrators.
Fix within
Internet-facing 3 days
Internal 60 days
  • Not known to be exploited
  • Can be exploited automatically
  • Gives an attacker full control
Severity
9.8 Critical
Exploitation
<1% chance of attack within 30 days
Type
CWE-269Improper Privilege Management
Timeline
Published8 Oct 2026
Updated10 Oct 2026
First seen8 Oct 2026
Sources
CVE-2026-103692 · MITRE
Track software like this
Free during beta