Ultimate Dashboard
cpe:2.3:a:davidvongries:ultimate_dashboard:*:*:*:*:wordpress:*:*
- <= 3.8.7
A vulnerability exists in the Ultimate Dashboard - Custom WordPress Dashboard plugin, affecting all versions through 3.8.7. The issue arises from a lack of proper capability checks in the handle_module_actions function, allowing authenticated attackers with Subscriber-level access or higher to unauthorizedly activate or deactivate plugin modules.
Exploitation of this vulnerability allows for unauthorized activation or deactivation of plugin modules by authenticated users with Subscriber-level access or above.
Users are advised to update the Ultimate Dashboard plugin to version 3.8.8 or a newer patched version.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.