The Frontend Dashboard plugin for WordPress is vulnerable to Privilege Escalation due to a missing capability check on the fed_admin_setting_form_function() function in versions 1.0 to 2.2.7. This makes it possible for authenticated attackers, with Subscriber-level access and above, to overwrite the plugin’s 'register' role setting to make new user registrations default to the administrator role, leading to an elevation of privileges to that of an administrator.
Metrics
Affected Vendors & Products
References
History
Tue, 13 May 2025 14:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Metrics |
ssvc
|
Tue, 13 May 2025 07:00:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | The Frontend Dashboard plugin for WordPress is vulnerable to Privilege Escalation due to a missing capability check on the fed_admin_setting_form_function() function in versions 1.0 to 2.2.7. This makes it possible for authenticated attackers, with Subscriber-level access and above, to overwrite the plugin’s 'register' role setting to make new user registrations default to the administrator role, leading to an elevation of privileges to that of an administrator. | |
Title | Frontend Dashboard 1.0 - 2.2.7 - Missing Authorization to Authenticated (Subscriber+) Privilege Escalation via fed_admin_setting_form_function Function | |
Weaknesses | CWE-285 | |
References |
|
|
Metrics |
cvssV3_1
|

Status: PUBLISHED
Assigner: Wordfence
Published: 2025-05-13T06:40:56.651Z
Updated: 2025-05-13T13:16:32.178Z
Reserved: 2025-05-08T19:57:39.408Z
Link: CVE-2025-4474

Updated: 2025-05-13T13:16:29.000Z

Status : Awaiting Analysis
Published: 2025-05-13T07:15:52.793
Modified: 2025-05-13T19:35:18.080
Link: CVE-2025-4474

No data.