---
id: CVE-2026-103692
title: >-
  The Frontend Dashboard WordPress plugin before 3.0.5 does not perform any
  authorisation or nonce check on actions available to unauthenticated users
  that call an attacker-chosen PHP function or class method with the request
  data, allowin…
summary: >-
  The Frontend Dashboard WordPress plugin before 3.0.5 does not perform any
  authorisation or nonce check on actions available to unauthenticated users
  that call an attacker-chosen PHP function or class method with the request
  data, allowin…
severity: none
cwe:
  - CWE-269
product: Frontend Dashboard
affected:
  - frontend_dashboard >= 3.0.0 < 3.0.5
published: '2026-10-08'
updated: '2026-10-08'
sourceUpdated: '2026-10-08T06:16:38.323'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-103692'
references:
  - url: 'https://wpscan.com/vulnerability/d2341538-77fa-48a0-83e3-bc9a3818276c/'
    label: contact@wpscan.com
tags:
  - nvd
  - cve.org
ingestedAt: '2026-10-08T07:18:54.836Z'
---

## Overview

The Frontend Dashboard WordPress plugin before 3.0.5 does not perform any authorisation or nonce check on actions available to unauthenticated users that call an attacker-chosen PHP function or class method with the request data, allowing unauthenticated users to take over any account, including administrators.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
