CRITICAL 9.8 CVE-2026-103692 Published 8 Oct 2026

Frontend Dashboard WordPress Plugin Account Takeover Vulnerability

Worried this affects your website?

The Frontend Dashboard WordPress plugin before 3.0.5 contains a missing authorization vulnerability.

Actions available to unauthenticated users do not perform any authorization or nonce check, allowing an attacker to call an attacker-chosen PHP function or class method with request data.

  • Affected versions: before 3.0.5
  • Precondition: unauthenticated access
  • Impact: full account takeover, including administrator accounts

Reference: CVE-2026-103692 on NVD

← Back to Security News