PT-2025-20067 · WordPress · Frontend Dashboard
Kenneth Dunn
·
Published
2025-05-07
·
Updated
2025-05-12
·
CVE-2025-4104
CVSS v3.1
9.8
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Frontend Dashboard plugin for WordPress versions 1.0 through 2.2.6
Description
The Frontend Dashboard plugin for WordPress is vulnerable to privilege escalation due to a missing capability check on the
fed wp ajax fed login form post() function. This allows unauthenticated attackers to reset the administrator's email and password, and elevate their privileges to that of an administrator.Recommendations
For versions 1.0 through 2.2.6, consider disabling the
fed wp ajax fed login form post() function until a patch is available to prevent exploitation. Restrict access to the administrator's account and monitor for any suspicious activity. Update to a version that includes a fix for this issue as soon as it becomes available.Fix
LPE
Improper Authorization
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Frontend Dashboard