Track vulnerabilities like this one.
Sign up free to get alerted when software you use is affected.
9.8
CVE-2026-103692: Frontend Dashboard plugin lets anyone hijack admin accounts
CVE-2026-103692 · published 2 days ago
Summary
The Frontend Dashboard WordPress plugin versions 3.0.0 through 3.0.4 let people who are not logged in run any code on your site, which can give them control of any user account, including administrators. This happens because the plugin does not check who is making the request. Update the plugin to version 3.0.5 or later, or remove it, to stop the risk.
What to do
- Update unknown frontend dashboard to version 3.0.5 or later.
Affected software
| Vendor | Product | Affected versions |
|---|---|---|
| unknown | frontend dashboard | < 3.0.5 |
Original advisory text
Frontend Dashboard 3.0.0 - 3.0.4 - Unauthenticated Privilege Escalation via Arbitrary Function Call
The Frontend Dashboard WordPress plugin before 3.0.5 does not perform any authorisation or nonce check on actions available to unauthenticated users that call an attacker-chosen PHP function or class method with the request data, allowing unauthenticated users to take over any account, including administrators.
Internet-facing
3 days
Internal
60 days
- Not known to be exploited
- Can be exploited automatically
- Gives an attacker full control
Severity
9.8
Critical
Type
CWE-269Improper Privilege Management
Timeline
Published8 Oct 2026
Updated10 Oct 2026
First seen8 Oct 2026
Track software like this
Free during beta