Eklenti güvenlik geçmişi
Frontend Dashboard güvenlik açıkları
ABD Ulusal Güvenlik Açığı Veritabanı’nda (NVD) Frontend Dashboard eklentisi için 10 açık kaydı bulunuyor; en yenisi 8 Ekim 2026 tarihli. Bunların 7 tanesi kritik veya yüksek önemde, 4 tanesi oturum açmadan istismar edilebiliyor. Güncel sürüm 3.0.7.
- Toplam kayıt
- 10
- Kritik veya yüksek
- 7
- Oturumsuz istismar
- 4
- Son kayıt
- 8 Ekim 2026
Bilinen açık kayıtları
En yeniden eskiye. Her kaydın özgün metni NVD’de.
yetki yükseltme
Etkilenen sürümler: 3.0.5 öncesi · Oturum açmadan istismar edilebilir
The Frontend Dashboard WordPress plugin before 3.0.5 does not perform any authorisation or nonce check on actions available to unauthenticated users that call an attacker-chosen PHP function or class method with the request data, allowing unauthenticated users to take over any account, including administrators.
Türkçe kayıt ve ne yapmalıeksik yetki denetimi
Etkilenen sürümler: 3.0.0 öncesi
The Frontend Dashboard WordPress plugin before 3.0.0 does not perform a capability check in one of its AJAX actions, allowing authenticated users with low privileges, such as subscribers, to delete the Frontend Dashboard WordPress plugin before 3.0.0's configured profile and post form fields.
depolanmış siteler arası betik çalıştırma (XSS)
Etkilenen sürümler: 2.2.8 ve öncesi
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in M A Vinoth Kumar Frontend Dashboard frontend-dashboard allows Stored XSS.This issue affects Frontend Dashboard: from n/a through <= 2.2.8.
yetki yükseltme
Etkilenen sürümler: Kayıtta belirtilmemiş
The Frontend Dashboard plugin for WordPress is vulnerable to Privilege Escalation due to a missing capability check on the fed_admin_setting_form_function() function in versions 1.0 to 2.2.7. This makes it possible for authenticated attackers, with Subscriber-level access and above, to overwrite the plugin’s 'register' role setting to make new user registrations default to the administrator role, leading to an elevation of privileges to that of an administrator.
yetki yükseltme
Etkilenen sürümler: Kayıtta belirtilmemiş
The Frontend Dashboard plugin for WordPress is vulnerable to Privilege Escalation due to a missing capability check on the ajax_request() function in versions 1.0 to 2.2.7. This makes it possible for authenticated attackers, with Subscriber-level access and above, to control where the plugin sends outgoing emails. By pointing SMTP to their own server, attackers could capture password reset emails intended for administrators, and elevate their privileges for full site takeover.
yetki yükseltme
Etkilenen sürümler: Kayıtta belirtilmemiş · Oturum açmadan istismar edilebilir
The Frontend Dashboard plugin for WordPress is vulnerable to Privilege Escalation due to a missing capability check on the fed_wp_ajax_fed_login_form_post() function in versions 1.0 to 2.2.6. This makes it possible for unauthenticated attackers to reset the administrator’s email and password, and elevate their privileges to that of an administrator.
SQL enjeksiyonu
Etkilenen sürümler: 2.2.5 ve öncesi · Oturum açmadan istismar edilebilir
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in M A Vinoth Kumar Frontend Dashboard frontend-dashboard allows SQL Injection.This issue affects Frontend Dashboard: from n/a through <= 2.2.5.
yetki yükseltme
Etkilenen sürümler: 2.2.4 ve öncesi
The Frontend Dashboard plugin for WordPress is vulnerable to unauthorized code execution due to insufficient filtering on callable methods/functions via the ajax_request() function in all versions up to, and including, 2.2.4. This makes it possible for authenticated attackers, with subscriber-level access and above, to call arbitrary functions that can be leverage for privilege escalation by changing user's passwords.
hassas bilgi ifşası
Etkilenen sürümler: 2.2.2 ve öncesi · Oturum açmadan istismar edilebilir
Exposure of Sensitive Information to an Unauthorized Actor vulnerability in vinoth06. Frontend Dashboard.This issue affects Frontend Dashboard: from n/a through 2.2.2.
depolanmış siteler arası betik çalıştırma (XSS)
Etkilenen sürümler: 2.2.1 ve öncesi
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in vinoth06. Frontend Dashboard allows Stored XSS.This issue affects Frontend Dashboard: from n/a through 2.2.1.
Kaynak: NVD (kamu malı veri) ve WordPress.org eklenti dizini. Kayıtlar eklentinin WordPress.org adresi veya tam adıyla eşleştirilir. Veri 8 Ekim 2026 itibarıyla.