WPHizmet

Eklenti güvenlik geçmişi

Frontend Dashboard güvenlik açıkları

ABD Ulusal Güvenlik Açığı Veritabanı’nda (NVD) Frontend Dashboard eklentisi için 10 açık kaydı bulunuyor; en yenisi 8 Ekim 2026 tarihli. Bunların 7 tanesi kritik veya yüksek önemde, 4 tanesi oturum açmadan istismar edilebiliyor. Güncel sürüm 3.0.7.

Toplam kayıt
10
Kritik veya yüksek
7
Oturumsuz istismar
4
Son kayıt
8 Ekim 2026

Bilinen açık kayıtları

En yeniden eskiye. Her kaydın özgün metni NVD’de.

  • CVE-2026-103692Kritik · 9,88 Ekim 2026

    yetki yükseltme

    Etkilenen sürümler: 3.0.5 öncesi · Oturum açmadan istismar edilebilir

    The Frontend Dashboard WordPress plugin before 3.0.5 does not perform any authorisation or nonce check on actions available to unauthenticated users that call an attacker-chosen PHP function or class method with the request data, allowing unauthenticated users to take over any account, including administrators.

    Türkçe kayıt ve ne yapmalı
  • CVE-2026-103681Orta · 4,37 Ekim 2026

    eksik yetki denetimi

    Etkilenen sürümler: 3.0.0 öncesi

    The Frontend Dashboard WordPress plugin before 3.0.0 does not perform a capability check in one of its AJAX actions, allowing authenticated users with low privileges, such as subscribers, to delete the Frontend Dashboard WordPress plugin before 3.0.0's configured profile and post form fields.

  • CVE-2025-49310Orta · 6,56 Haziran 2025

    depolanmış siteler arası betik çalıştırma (XSS)

    Etkilenen sürümler: 2.2.8 ve öncesi

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in M A Vinoth Kumar Frontend Dashboard frontend-dashboard allows Stored XSS.This issue affects Frontend Dashboard: from n/a through <= 2.2.8.

  • CVE-2025-4474Yüksek · 8,813 Mayıs 2025

    yetki yükseltme

    Etkilenen sürümler: Kayıtta belirtilmemiş

    The Frontend Dashboard plugin for WordPress is vulnerable to Privilege Escalation due to a missing capability check on the fed_admin_setting_form_function() function in versions 1.0 to 2.2.7. This makes it possible for authenticated attackers, with Subscriber-level access and above, to overwrite the plugin’s 'register' role setting to make new user registrations default to the administrator role, leading to an elevation of privileges to that of an administrator.

  • CVE-2025-4473Yüksek · 8,813 Mayıs 2025

    yetki yükseltme

    Etkilenen sürümler: Kayıtta belirtilmemiş

    The Frontend Dashboard plugin for WordPress is vulnerable to Privilege Escalation due to a missing capability check on the ajax_request() function in versions 1.0 to 2.2.7. This makes it possible for authenticated attackers, with Subscriber-level access and above, to control where the plugin sends outgoing emails. By pointing SMTP to their own server, attackers could capture password reset emails intended for administrators, and elevate their privileges for full site takeover.

  • CVE-2025-4104Kritik · 9,87 Mayıs 2025

    yetki yükseltme

    Etkilenen sürümler: Kayıtta belirtilmemiş · Oturum açmadan istismar edilebilir

    The Frontend Dashboard plugin for WordPress is vulnerable to Privilege Escalation due to a missing capability check on the fed_wp_ajax_fed_login_form_post() function in versions 1.0 to 2.2.6. This makes it possible for unauthenticated attackers to reset the administrator’s email and password, and elevate their privileges to that of an administrator.

  • CVE-2025-46248Kritik · 9,324 Nisan 2025

    SQL enjeksiyonu

    Etkilenen sürümler: 2.2.5 ve öncesi · Oturum açmadan istismar edilebilir

    Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in M A Vinoth Kumar Frontend Dashboard frontend-dashboard allows SQL Injection.This issue affects Frontend Dashboard: from n/a through <= 2.2.5.

  • CVE-2024-8268Yüksek · 8,810 Eylül 2024

    yetki yükseltme

    Etkilenen sürümler: 2.2.4 ve öncesi

    The Frontend Dashboard plugin for WordPress is vulnerable to unauthorized code execution due to insufficient filtering on callable methods/functions via the ajax_request() function in all versions up to, and including, 2.2.4. This makes it possible for authenticated attackers, with subscriber-level access and above, to call arbitrary functions that can be leverage for privilege escalation by changing user's passwords.

  • CVE-2024-32726Yüksek · 7,524 Nisan 2024

    hassas bilgi ifşası

    Etkilenen sürümler: 2.2.2 ve öncesi · Oturum açmadan istismar edilebilir

    Exposure of Sensitive Information to an Unauthorized Actor vulnerability in vinoth06. Frontend Dashboard.This issue affects Frontend Dashboard: from n/a through 2.2.2.

  • CVE-2024-29775Orta · 6,527 Mart 2024

    depolanmış siteler arası betik çalıştırma (XSS)

    Etkilenen sürümler: 2.2.1 ve öncesi

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in vinoth06. Frontend Dashboard allows Stored XSS.This issue affects Frontend Dashboard: from n/a through 2.2.1.

Kaynak: NVD (kamu malı veri) ve WordPress.org eklenti dizini. Kayıtlar eklentinin WordPress.org adresi veya tam adıyla eşleştirilir. Veri 8 Ekim 2026 itibarıyla.