CVE-2024-8268
10.09.2024, 03:15
The Frontend Dashboard plugin for WordPress is vulnerable to unauthorized code execution due to insufficient filtering on callable methods/functions via the ajax_request() function in all versions up to, and including, 2.2.4. This makes it possible for authenticated attackers, with subscriber-level access and above, to call arbitrary functions that can be leverage for privilege escalation by changing user's passwords.
Vendor | Product | Version |
---|---|---|
buffercode | frontend_dashboard | 𝑥 ≤ 2.2.4 |
buffercode | frontend_dashboard | 𝑥 < 2.2.5 |
𝑥
= Vulnerable software versions
References