Unauthorized Data Access Vulnerability in Material Dashboard Plugin for WordPress
CVE-2026-6079
7.3HIGH
What is CVE-2026-6079?
The Material Dashboard plugin for WordPress contains a vulnerability that permits unauthorized users to access and modify data due to inadequate capability checks in the amd_ajax_target_task_manager() function. This issue exists in all versions up to and including 1.4.10. As a result, unauthenticated attackers can enumerate scheduled tasks, possibly exposing personal identifiable information (PII), execute arbitrary tasks, and delete any scheduled task through the public_amd_ajax_handler AJAX action, compromising the integrity of the system.
Affected Version(s)
Material Dashboard 0 <= 1.4.10