CVE-2025-4104

Published
View on NVD ↗
CVSS v3
9.8
CRITICAL
CVSS v2
N/A
Affected
1
PROJECT

Description

The Frontend Dashboard plugin for WordPress is vulnerable to Privilege Escalation due to a missing capability check on the fed_wp_ajax_fed_login_form_post() function in versions 1.0 to 2.2.6. This makes it possible for unauthenticated attackers to reset the administrator’s email and password, and elevate their privileges to that of an administrator.

<h4>Frontend Dashboard Designed and Developed with WordPress Coding Standards</h4> <p>Frontend Dashboard is bundled with the huge list of custom features which can easily customise the User profile, Posts, Login, Register, Custom roles on the custom front page.</p> <ol> <li>Custom Login Page.</li> <li>Custom Register Page.</li> <li>Custom Forgot Password.</li> <li>Custom Redirect URL for before and after Login, Register, Logout.</li> <li>Restrict WP Admin area for role based users.</li> <li>Add/Delete custom User Roles.</li> <li>Customise the Frontend Dashboard with your theme matching colors.</li> <li>Enable/Disable the Frontend Dashboard scripts and styles on both frontend and admin.</li> <li>Add Frontend Dashboard menus for User based roles.</li> <li>Add any number of custom user field.</li> <li>Add any number of post/custom post field.</li> <li>Each custom fields can be configured based on user roles.</li> <li>Allow/Disallow to upload files in Frontend Dashboard based on User Role.</li> <li>Show custom user fields on Register page.</li> <li>Add/Edit/Delete Post/Custom post in Frontend Dashboard based on User Role.</li> <li>Show user role based custom profile page.</li> <li>Manage custom Post type and Taxonomies.</li> <li>Customize templates.</li> <li>Restrict illegal username on Registration.</li> </ol> <h4>Frontend Dashboard Plugins List</h4> <ul> <li><a href="https://buffercode.com/plugin/frontend-dashboard-user-management" rel="nofollow ugc">Frontend Dashboard User Management (Pro) </a></li> <li><a href="https://buffercode.com/plugin/frontend-dashboard-social-connect" rel="nofollow ugc">Frontend Dashboard Social Connect (Pro) </a></li> <li><a href="https://buffercode.com/plugin/frontend-dashboard-pages" rel="nofollow ugc">Frontend Dashboard Pages</a></li> <li><a href="https://buffercode.com/plugin/frontend-dashboard-extra" rel="nofollow ugc">Frontend Dashboard Extra</a></li> <li><a href="https://buffercode.com/plugin/frontend-dashboard-captcha" rel="nofollow ugc">Frontend Dashboard Captcha</a></li> <li><a href="https://buffercode.com/plugin/frontend-dashboard-templates" rel="nofollow ugc">Frontend Dashboard Templates</a></li> <li><a href="https://buffercode.com/plugin/frontend-dashboard-social-chat" rel="nofollow ugc">Frontend Dashboard Social Chat</a></li> <li><a href="https://buffercode.com/plugin/frontend-dashboard-notification" rel="nofollow ugc">Frontend Dashboard Notification</a></li> <li><a href="https://buffercode.com/plugin/frontend-dashboard-custom-post-and-taxonomies" rel="nofollow ugc">Frontend Dashboard Custom Post and Taxonomies</a></li> </ul> <h4>Videos</h4> <p><strong>How to Setup Frontend Dashboard and its Add-on</strong></p> <p><span class="embed-youtube" style="text-align:center; display: block;"><iframe loading="lazy" class="youtube-player" width="750" height="422" src="https://www.youtube.com/embed/lyoUkwndoRA?version=3&#038;rel=1&#038;showsearch=0&#038;showinfo=1&#038;iv_load_policy=1&#038;fs=1&#038;hl=en-US&#038;autohide=2&#038;wmode=transparent" allowfullscreen="true" style="border:0;" sandbox="allow-scripts allow-same-origin allow-popups allow-presentation allow-popups-to-escape-sandbox"></iframe></span></p> <p>For more video : <a href="https://buffercode.com/category/name/frontend-dashboard" rel="nofollow ugc">Frontend Dashboard</a></p> <ul> <li> <p><a href="https://buffercode.com/post/how-to-setup-payment-and-membership-pro" rel="nofollow ugc">How to setup Membership and Payment (PRO)</a></p> </li> <li> <p><a href="https://buffercode.com/post/how-to-show-custom-post-field-in-frontend-post" rel="nofollow ugc">How to show custom post field in Frontend Post</a></p> </li> <li> <p><a href="https://buffercode.com/post/how-to-translate-frontend-dashboard" rel="nofollow ugc">How to Translate Frontend Dashboard</a></p> </li> <li> <p><a href="https://buffercode.com/post/how-to-create-custom-login-for-frontend-dashboard-wordpress-plugin" rel="nofollow ugc">How to create custom login for Frontend Dashboard</a></p> </li> <li> <p><a href="https://buffercode.com/post/how-to-create-dashboard-for-frontend-dashboard-wordpress-plugin" rel="nofollow ugc">How to create Dashboard for Frontend Dashboard</a></p> </li> <li> <p><a href="https://buffercode.com/post/how-to-set-redirect-on-login-for-frontend-dashboard-wordpress-plugin" rel="nofollow ugc">How to set Redirect on Login for Frontend Dashboard</a></p> </li> <li> <p><a href="https://buffercode.com/post/how-to-set-widget-for-frontend-dashboard-wordpress-plugin" rel="nofollow ugc">How to set Widget for Frontend Dashboard</a></p> </li> <li> <p><a href="https://buffercode.com/post/how-to-create-custom-user-role-in-frontend-dashboard-wordpress-plugin" rel="nofollow ugc">How to Create Custom User Role in Frontend Dashboard</a></p> </li> <li> <p><a href="https://buffercode.com/post/how-to-create-a-page-for-users-based-on-their-user-role" rel="nofollow ugc">How to create a page for Users, based on their User Role</a></p> </li> <li> <p><a href="https://buffercode.com/post/how-new-user-can-select-user-role-on-registration" rel="nofollow ugc">How new user can select user role on registration</a></p> </li> <li> <p><a href="https://buffercode.com/post/how-to-customise-the-layout-colours-in-frontend-dashboard" rel="nofollow ugc">How to customise the layout colours in Frontend Dashboard</a></p> </li> <li> <p><a href="https://buffercode.com/post/how-to-manage-post-options-in-frontend-dashboard" rel="nofollow ugc">How to manage post options in Frontend Dashboard</a></p> </li> <li> <p><a href="https://buffercode.com/post/how-to-create-custom-menu-in-frontend-dashboard" rel="nofollow ugc">How to create custom menu in Frontend Dashboard</a></p> </li> </ul> <p>For more video : <a href="https://buffercode.com/category/name/frontend-dashboard" rel="nofollow ugc">Frontend Dashboard</a></p>
WordPress Plugin DirectoryWordPress Plugin Directory
146K