CVE-2026-103692
Description
AI Translation Available
The Frontend Dashboard WordPress plugin before 3.0.5 does not perform any authorisation or nonce check on actions available to unauthenticated users that call an attacker-chosen PHP function or class method with the request data, allowing unauthenticated users to take over any account, including administrators.
https://wpscan.com/vulnerability/d2341538-77fa-48a0-83e3-bc9a3818276c/