{"id":"CVE-2026-103692","title":"The Frontend Dashboard WordPress plugin before 3.0.5 does not perform any authorisation or nonce check on actions available to unauthenticated users that call an attacker-chosen PHP function or class method with the request data, allowin…","summary":"The Frontend Dashboard WordPress plugin before 3.0.5 does not perform any authorisation or nonce check on actions available to unauthenticated users that call an attacker-chosen PHP function or class method with the request data, allowin…","severity":"none","cwe":["CWE-269"],"product":"Frontend Dashboard","affected":["frontend_dashboard >= 3.0.0 < 3.0.5"],"published":"2026-10-08","updated":"2026-10-08","sourceUpdated":"2026-10-08T06:16:38.323","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-103692","references":[{"url":"https://wpscan.com/vulnerability/d2341538-77fa-48a0-83e3-bc9a3818276c/","label":"contact@wpscan.com"}],"tags":["nvd","cve.org"],"ingestedAt":"2026-10-08T07:18:54.836Z","slug":"CVE-2026-103692","body":"## Overview\n\nThe Frontend Dashboard WordPress plugin before 3.0.5 does not perform any authorisation or nonce check on actions available to unauthenticated users that call an attacker-chosen PHP function or class method with the request data, allowing unauthenticated users to take over any account, including administrators.\n\n## Remediation\n\nRefer to the linked advisories for vendor-supplied fixes and affected version ranges.","depth":"sunlit","depthScore":3,"depthScoreParts":{"impact":2.8,"likelihood":0,"exploitation":0,"ransomware":0},"changes":[]}