Sceawere
Vulnerability Detail
CVE-2026-103692UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV
Frontend Dashboard Unauthenticated RCE/Privilege Escalation
Vulnerability Metadata
- Severity
- Critical
- Score / CVSS
- 9.8
- Creation Date
- 8h ago
- Vendor
- Unknown
- Product
- Frontend Dashboard
- Attack Type
- CWE-269 Improper Privilege Management
- Vector String
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
- Attack Complexity
- LOW
Narrative and Response
Description
The Frontend Dashboard WordPress plugin before 3.0.5 does not perform any authorisation or nonce check on actions available to unauthenticated users that call an attacker-chosen PHP function or class method with the request data, allowing unauthenticated users to take over any account, including administrators.
Executive Summary
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Technical Details
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Mitigations
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
References
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Additional Metadata
{
"score": "9.8",
"pubDate": "2026-10-08T06:16:38.323Z",
"pubdate": "2026-10-08T06:16:38.323Z",
"executiveSummary": "The Frontend Dashboard WordPress plugin, prior to version 3.0.5, contains a critical security vulnerability involving improper authorization and lack of nonce verification.\nThis flaw allows unauthenticated, remote attackers to trigger arbitrary PHP functions or class methods using attacker-supplied request data.\nThe vulnerability poses a severe risk, as it enables full administrative account takeover and potential remote code execution (RCE) on affected WordPress installations.\nBecause the vulnerable action endpoints are exposed to unauthenticated users without nonce validation, the barrier to exploitation is extremely low.\nSuccessful exploitation results in total site compromise, including the ability to modify content, install malicious plugins, exfiltrate data, or execute arbitrary system-level commands within the context of the web server.\nThis issue represents an critical security flaw that requires immediate remediation by updating to the patched version of the plugin.",
"technicalDetails": "The root cause of this vulnerability lies in the improper handling of AJAX actions within the Frontend Dashboard plugin. The plugin implements a request handler that fails to enforce authorization checks or validate cryptographic nonces for critical operations available to the public.\nThe affected component exposes an interface that dynamically invokes PHP functions or class methods based on user-supplied parameters. Because the input parameters are not sanitized or restricted against a whitelist of safe functions, the application facilitates a dynamic function execution vulnerability.\nThe exploitation flow begins when an unauthenticated attacker sends a crafted HTTP POST request to the WordPress admin-ajax.php endpoint. This request includes parameters that specify the target class method or function name and the associated data payload.\nSince the plugin's internal dispatcher lacks a gatekeeper function—specifically omitting the check_ajax_referer() function or similar access control checks—the server processes the input and executes the attacker-defined target with the provided arguments.\nBy targeting specific plugin methods that handle user session management or administrative privilege assignment, an attacker can manipulate the internal state of the WordPress user database. Specifically, by invoking methods that process user registration or profile updates without verifying the caller's identity, an attacker can elevate their own privileges to the 'Administrator' role.\nFurthermore, the ability to invoke arbitrary class methods opens a path for remote code execution. An attacker may identify existing classes within the WordPress environment that perform sensitive operations when supplied with specific parameters, potentially chaining the function call to achieve arbitrary code execution via file system interaction or administrative configuration changes.\nThe vulnerability is present in all versions of the Frontend Dashboard plugin prior to 3.0.5. The attack vector is strictly network-based and requires no prior authentication, making it highly attractive for automated exploitation attempts targeting unpatched WordPress sites.\nPost-exploitation, the impact is total site compromise. The attacker can effectively seize control of the WordPress environment, leading to full data exposure, site defacement, or persistence through the injection of backdoored themes and plugins."
}