Cross-Site Request Forgery in Ultimate Dashboard Plugin for WordPress
CVE-2026-3140
4.3MEDIUM
Key Information:
- Vendor
WordPress
- Vendor
- CVE Published:
- 1 May 2026
What is CVE-2026-3140?
The Ultimate Dashboard plugin for WordPress has a vulnerability that allows unauthenticated attackers to exploit Cross-Site Request Forgery (CSRF). This vulnerability arises from a flawed nonce validation in the 'handle_module_actions' function, enabling attackers to toggle plugin modules on or off. The attack requires tricking a site administrator into executing a crafted request, which could lead to unauthorized changes in the plugin's configurations.
Affected Version(s)
Ultimate Dashboard β Custom WordPress Dashboard 0 <= 3.8.14