WordPress security by component
Material Dashboard
Plugin description
Material Dashboard is a WordPress component with 5 published CVE records in this archive. The latest tracked vulnerability was published Aug 05, 2026; the highest published CVSS base score is 9.8.
Plugin slug:
material-dashboardLatest vulnerability
CVE-2026-6079: Material Dashboard public task manager permits task disclosure, execution and deletion
Material Dashboard through 1.4.10 exposes public_amd_ajax_handler without a capability check before amd_ajax_target_task_manager() processes the request. An unauthenticated attacker can enumerate scheduled tasks, potentially exposing personal information, execute arbitrary registered tasks and delete tasks. The CNA does not disclose the operation parameter, task identifier, task-specific effects or lower-level functions.
| Safe version |
|
||
|---|---|---|---|
| Aug 05, 2026 |
CVE-2026-6079
Material Dashboard public task manager permits task disclosure, execution and deletion
Material Dashboard through 1.4.10 exposes public_amd_ajax_handler without a capability check before amd_ajax_target_task_manager() processes the request. An unauthenticated attacker can enumerate scheduled tasks, potentially exposing personal information, execute arbitrary registered tasks and delete tasks. The CNA does not disclose the operation parameter, task identifier, task-specific effects or lower-level functions.
|
> 1.4.10 |
CVE7.3
NVDPending
|
| Sep 09, 2025 |
CVE-2025-32486
Material Dashboard: A security weakness
Material Dashboard is affected by a security weakness. Exposure depends on how the affected operation is made reachable by the site. The resulting impact depends on how the affected component exposes the vulnerable operation. The public source does not disclose the vulnerable endpoint, action, parameter or function, so the precise input path remains unknown.
|
See mitigation notes |
CVE9.8
NVDPending
|
| Apr 11, 2025 |
CVE-2025-31014
Material Dashboard: Filesystem traversal
Material Dashboard is affected by filesystem traversal. Exposure depends on how the affected operation is made reachable by the site. A crafted path can escape the intended directory and reach files or directories elsewhere on the server. The public source does not disclose the vulnerable endpoint, action, parameter or function, so the precise input path remains unknown.
|
See mitigation notes |
CVE7.5
NVDPending
|
| Apr 01, 2025 |
CVE-2025-31097
Material Dashboard: Filesystem traversal
Material Dashboard is affected by filesystem traversal. Exposure depends on how the affected operation is made reachable by the site. A crafted path can escape the intended directory and reach files or directories elsewhere on the server. The public source does not disclose the vulnerable endpoint, action, parameter or function, so the precise input path remains unknown.
|
See mitigation notes |
CVE8.1
NVDPending
|
| Apr 01, 2025 |
CVE-2025-31095
Material Dashboard: Privilege escalation or authentication bypass
Material Dashboard is affected by privilege escalation or authentication bypass. Exposure depends on how the affected operation is made reachable by the site. A successful request can grant permissions or access that the caller should not possess. The public source does not disclose the vulnerable endpoint, action, parameter or function, so the precise input path remains unknown.
|
See mitigation notes |
CVE9.8
NVDPending
|