Retour à la veille

CVE-2026-103681

Publié : 7 octobre 2026
Modifié : 7 octobre 2026
Lien officiel NVD

Description détaillée

The Frontend Dashboard WordPress plugin before 3.0.0 does not perform a capability check in one of its AJAX actions, allowing authenticated users with low privileges, such as subscribers, to delete the Frontend Dashboard WordPress plugin before 3.0.0's configured profile and post form fields.

Références et Patchs