Description
The Frontend Dashboard WordPress plugin before 3.0.0 does not perform a capability check in one of its AJAX actions, allowing authenticated users with low privileges, such as subscribers, to delete the Frontend Dashboard WordPress plugin before 3.0.0's configured profile and post form fields.
Published: 2026-10-07
Score: 4.3 Medium
EPSS: n/a
KEV: No
Impact: Unauthorized deletion of plugin configuration fields via improper authorization
Action: Apply patch
AI Analysis

Impact

The Frontend Dashboard WordPress plugin fails to verify user capabilities during an AJAX operation named fed_user_profile_delete. This oversight lets any authenticated user, including subscribers, remove the plugin’s predefined profile and post form fields. From a security standpoint, the flaw enables an attacker to tamper with the site’s data‑entry structures, affecting functionality and potentially compromising data integrity. The weakness belongs to the category of improper authorization.

Affected Systems

The vulnerability affects the Frontend Dashboard plugin for WordPress versions older than 3.0.0. Affected installations are those that have not applied the 3.0.0 release or later, and the flaw can be exploited only by authenticated users with low privileges, such as subscribers.

Risk and Exploitability

The exploit requires a valid authentication session and the ability to submit AJAX requests to the plugin’s endpoints. Because the plugin is common among WordPress sites, the attack surface is sizable, but the inability to achieve remote code execution limits the impact to configuration tampering rather than system compromise. The CVSS score is 4.3, indicating a moderate severity. No EPSS score is available, and the vulnerability is not listed in the CISA KEV catalog, suggesting the exploitation likelihood may be moderate. Administrators should therefore treat the issue as a medium‑to‑high risk until a patch is applied.

Generated by OpenCVE AI on October 7, 2026 at 11:55 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade the Frontend Dashboard plugin to version 3.0.0 or later to correct the capability check.
  • If immediate upgrade is not possible, restrict user roles that can trigger the AJAX action or remove the plugin entirely while the patch is pending.
  • Verify that the plugin does not expose any other AJAX endpoints without proper capability checks.

Generated by OpenCVE AI on October 7, 2026 at 11:55 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 07 Oct 2026 10:30:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 4.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 07 Oct 2026 08:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-284

Wed, 07 Oct 2026 06:30:00 +0000

Type Values Removed Values Added
Description The Frontend Dashboard WordPress plugin before 3.0.0 does not perform a capability check in one of its AJAX actions, allowing authenticated users with low privileges, such as subscribers, to delete the Frontend Dashboard WordPress plugin before 3.0.0's configured profile and post form fields.
Title Frontend Dashboard < 3.0.0 - Subscriber+ Profile and Post Field Deletion via fed_user_profile_delete
References

Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: WPScan

Published:

Updated: 2026-10-07T10:09:58.373Z

Reserved: 2026-10-01T09:16:45.756Z

Link: CVE-2026-103681

cve-icon Vulnrichment

Updated: 2026-10-07T09:59:16.501Z

cve-icon NVD

Status : Received

Published: 2026-10-07T07:16:57.260

Modified: 2026-10-07T11:17:09.690

Link: CVE-2026-103681

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-07T12:00:15Z

Weaknesses