CVE-2025-4473

Published
View on NVD ↗
CVSS v3
8.8
HIGH
CVSS v2
N/A
Affected
1
PROJECT

Description

The Frontend Dashboard plugin for WordPress is vulnerable to Privilege Escalation due to a missing capability check on the ajax_request() function in versions 1.0 to 2.2.7. This makes it possible for authenticated attackers, with Subscriber-level access and above, to control where the plugin sends outgoing emails. By pointing SMTP to their own server, attackers could capture password reset emails intended for administrators, and elevate their privileges for full site takeover.

<h4>Frontend Dashboard Designed and Developed with WordPress Coding Standards</h4> <p>Frontend Dashboard is bundled with the huge list of custom features which can easily customise the User profile, Posts, Login, Register, Custom roles on the custom front page.</p> <ol> <li>Custom Login Page.</li> <li>Custom Register Page.</li> <li>Custom Forgot Password.</li> <li>Custom Redirect URL for before and after Login, Register, Logout.</li> <li>Restrict WP Admin area for role based users.</li> <li>Add/Delete custom User Roles.</li> <li>Customise the Frontend Dashboard with your theme matching colors.</li> <li>Enable/Disable the Frontend Dashboard scripts and styles on both frontend and admin.</li> <li>Add Frontend Dashboard menus for User based roles.</li> <li>Add any number of custom user field.</li> <li>Add any number of post/custom post field.</li> <li>Each custom fields can be configured based on user roles.</li> <li>Allow/Disallow to upload files in Frontend Dashboard based on User Role.</li> <li>Show custom user fields on Register page.</li> <li>Add/Edit/Delete Post/Custom post in Frontend Dashboard based on User Role.</li> <li>Show user role based custom profile page.</li> <li>Manage custom Post type and Taxonomies.</li> <li>Customize templates.</li> <li>Restrict illegal username on Registration.</li> </ol> <h4>Frontend Dashboard Plugins List</h4> <ul> <li><a href="https://buffercode.com/plugin/frontend-dashboard-user-management" rel="nofollow ugc">Frontend Dashboard User Management (Pro) </a></li> <li><a href="https://buffercode.com/plugin/frontend-dashboard-social-connect" rel="nofollow ugc">Frontend Dashboard Social Connect (Pro) </a></li> <li><a href="https://buffercode.com/plugin/frontend-dashboard-pages" rel="nofollow ugc">Frontend Dashboard Pages</a></li> <li><a href="https://buffercode.com/plugin/frontend-dashboard-extra" rel="nofollow ugc">Frontend Dashboard Extra</a></li> <li><a href="https://buffercode.com/plugin/frontend-dashboard-captcha" rel="nofollow ugc">Frontend Dashboard Captcha</a></li> <li><a href="https://buffercode.com/plugin/frontend-dashboard-templates" rel="nofollow ugc">Frontend Dashboard Templates</a></li> <li><a href="https://buffercode.com/plugin/frontend-dashboard-social-chat" rel="nofollow ugc">Frontend Dashboard Social Chat</a></li> <li><a href="https://buffercode.com/plugin/frontend-dashboard-notification" rel="nofollow ugc">Frontend Dashboard Notification</a></li> <li><a href="https://buffercode.com/plugin/frontend-dashboard-custom-post-and-taxonomies" rel="nofollow ugc">Frontend Dashboard Custom Post and Taxonomies</a></li> </ul> <h4>Videos</h4> <p><strong>How to Setup Frontend Dashboard and its Add-on</strong></p> <p><span class="embed-youtube" style="text-align:center; display: block;"><iframe loading="lazy" class="youtube-player" width="750" height="422" src="https://www.youtube.com/embed/lyoUkwndoRA?version=3&#038;rel=1&#038;showsearch=0&#038;showinfo=1&#038;iv_load_policy=1&#038;fs=1&#038;hl=en-US&#038;autohide=2&#038;wmode=transparent" allowfullscreen="true" style="border:0;" sandbox="allow-scripts allow-same-origin allow-popups allow-presentation allow-popups-to-escape-sandbox"></iframe></span></p> <p>For more video : <a href="https://buffercode.com/category/name/frontend-dashboard" rel="nofollow ugc">Frontend Dashboard</a></p> <ul> <li> <p><a href="https://buffercode.com/post/how-to-setup-payment-and-membership-pro" rel="nofollow ugc">How to setup Membership and Payment (PRO)</a></p> </li> <li> <p><a href="https://buffercode.com/post/how-to-show-custom-post-field-in-frontend-post" rel="nofollow ugc">How to show custom post field in Frontend Post</a></p> </li> <li> <p><a href="https://buffercode.com/post/how-to-translate-frontend-dashboard" rel="nofollow ugc">How to Translate Frontend Dashboard</a></p> </li> <li> <p><a href="https://buffercode.com/post/how-to-create-custom-login-for-frontend-dashboard-wordpress-plugin" rel="nofollow ugc">How to create custom login for Frontend Dashboard</a></p> </li> <li> <p><a href="https://buffercode.com/post/how-to-create-dashboard-for-frontend-dashboard-wordpress-plugin" rel="nofollow ugc">How to create Dashboard for Frontend Dashboard</a></p> </li> <li> <p><a href="https://buffercode.com/post/how-to-set-redirect-on-login-for-frontend-dashboard-wordpress-plugin" rel="nofollow ugc">How to set Redirect on Login for Frontend Dashboard</a></p> </li> <li> <p><a href="https://buffercode.com/post/how-to-set-widget-for-frontend-dashboard-wordpress-plugin" rel="nofollow ugc">How to set Widget for Frontend Dashboard</a></p> </li> <li> <p><a href="https://buffercode.com/post/how-to-create-custom-user-role-in-frontend-dashboard-wordpress-plugin" rel="nofollow ugc">How to Create Custom User Role in Frontend Dashboard</a></p> </li> <li> <p><a href="https://buffercode.com/post/how-to-create-a-page-for-users-based-on-their-user-role" rel="nofollow ugc">How to create a page for Users, based on their User Role</a></p> </li> <li> <p><a href="https://buffercode.com/post/how-new-user-can-select-user-role-on-registration" rel="nofollow ugc">How new user can select user role on registration</a></p> </li> <li> <p><a href="https://buffercode.com/post/how-to-customise-the-layout-colours-in-frontend-dashboard" rel="nofollow ugc">How to customise the layout colours in Frontend Dashboard</a></p> </li> <li> <p><a href="https://buffercode.com/post/how-to-manage-post-options-in-frontend-dashboard" rel="nofollow ugc">How to manage post options in Frontend Dashboard</a></p> </li> <li> <p><a href="https://buffercode.com/post/how-to-create-custom-menu-in-frontend-dashboard" rel="nofollow ugc">How to create custom menu in Frontend Dashboard</a></p> </li> </ul> <p>For more video : <a href="https://buffercode.com/category/name/frontend-dashboard" rel="nofollow ugc">Frontend Dashboard</a></p>
WordPress Plugin DirectoryWordPress Plugin Directory
146K