Impact
The Frontend Dashboard WordPress plugin fails to verify user capabilities during an AJAX operation named fed_user_profile_delete. This oversight lets any authenticated user, including subscribers, remove the plugin’s predefined profile and post form fields. From a security standpoint, the flaw enables an attacker to tamper with the site’s data‑entry structures, affecting functionality and potentially compromising data integrity. The weakness belongs to the category of improper authorization.
Affected Systems
The vulnerability affects the Frontend Dashboard plugin for WordPress versions older than 3.0.0. Affected installations are those that have not applied the 3.0.0 release or later, and the flaw can be exploited only by authenticated users with low privileges, such as subscribers.
Risk and Exploitability
The exploit requires a valid authentication session and the ability to submit AJAX requests to the plugin’s endpoints. Because the plugin is common among WordPress sites, the attack surface is sizable, but the inability to achieve remote code execution limits the impact to configuration tampering rather than system compromise. The CVSS score is 4.3, indicating a moderate severity. No EPSS score is available, and the vulnerability is not listed in the CISA KEV catalog, suggesting the exploitation likelihood may be moderate. Administrators should therefore treat the issue as a medium‑to‑high risk until a patch is applied.
OpenCVE Enrichment