← WordPress Vulnerabilities
WordPress security by component

Material Dashboard

Material Dashboard is a WordPress component with 5 published CVE records in this archive. The latest tracked vulnerability was published Aug 05, 2026; the highest published CVSS base score is 9.8.

Plugin slug: material-dashboard

CVE-2026-6079: Material Dashboard public task manager permits task disclosure, execution and deletion

Material Dashboard through 1.4.10 exposes public_amd_ajax_handler without a capability check before amd_ajax_target_task_manager() processes the request. An unauthenticated attacker can enumerate scheduled tasks, potentially exposing personal information, execute arbitrary registered tasks and delete tasks. The CNA does not disclose the operation parameter, task identifier, task-specific effects or lower-level functions.

PublishedAug 05, 2026
Known safe version> 1.4.10
Published vulnerabilities for material-dashboard
Safe version
Aug 05, 2026 CVE-2026-6079
Material Dashboard public task manager permits task disclosure, execution and deletion
Material Dashboard through 1.4.10 exposes public_amd_ajax_handler without a capability check before amd_ajax_target_task_manager() processes the request. An unauthenticated attacker can enumerate scheduled tasks, potentially exposing personal information, execute arbitrary registered tasks and delete tasks. The CNA does not disclose the operation parameter, task identifier, task-specific effects or lower-level functions.
> 1.4.10
CVE7.3
NVDPending
Sep 09, 2025 CVE-2025-32486
Material Dashboard: A security weakness
Material Dashboard is affected by a security weakness. Exposure depends on how the affected operation is made reachable by the site. The resulting impact depends on how the affected component exposes the vulnerable operation. The public source does not disclose the vulnerable endpoint, action, parameter or function, so the precise input path remains unknown.
See mitigation notes
CVE9.8
NVDPending
Apr 11, 2025 CVE-2025-31014
Material Dashboard: Filesystem traversal
Material Dashboard is affected by filesystem traversal. Exposure depends on how the affected operation is made reachable by the site. A crafted path can escape the intended directory and reach files or directories elsewhere on the server. The public source does not disclose the vulnerable endpoint, action, parameter or function, so the precise input path remains unknown.
See mitigation notes
CVE7.5
NVDPending
Apr 01, 2025 CVE-2025-31097
Material Dashboard: Filesystem traversal
Material Dashboard is affected by filesystem traversal. Exposure depends on how the affected operation is made reachable by the site. A crafted path can escape the intended directory and reach files or directories elsewhere on the server. The public source does not disclose the vulnerable endpoint, action, parameter or function, so the precise input path remains unknown.
See mitigation notes
CVE8.1
NVDPending
Apr 01, 2025 CVE-2025-31095
Material Dashboard: Privilege escalation or authentication bypass
Material Dashboard is affected by privilege escalation or authentication bypass. Exposure depends on how the affected operation is made reachable by the site. A successful request can grant permissions or access that the caller should not possess. The public source does not disclose the vulnerable endpoint, action, parameter or function, so the precise input path remains unknown.
See mitigation notes
CVE9.8
NVDPending