← WordPress Vulnerabilities
WordPress security by component

Ultimate Dashboard – Custom WordPress Dashboard

Ultimate Dashboard – Custom WordPress Dashboard is a WordPress component with 9 published CVE records in this archive. The latest tracked vulnerability was published May 01, 2026; the highest CVE/CNA score is 5.9.

Plugin slug: ultimate-dashboard

CVE-2026-3140: Ultimate Dashboard – Custom WordPress Dashboard: Cross-site request forgery

Ultimate Dashboard – Custom WordPress Dashboard is affected by cross-site request forgery. The vulnerable path is reachable without authentication. Exploitation relies on a signed-in privileged user submitting an attacker-controlled request. The published affected range is <= 3.8.14.

PublishedMay 01, 2026
Known safe version> 3.8.14
Safe version
May 01, 2026 CVE-2026-3140
Ultimate Dashboard – Custom WordPress Dashboard: Cross-site request forgery
Ultimate Dashboard – Custom WordPress Dashboard is affected by cross-site request forgery. The vulnerable path is reachable without authentication. Exploitation relies on a signed-in privileged user submitting an attacker-controlled request. The published affected range is <= 3.8.14.
> 3.8.14
CVE4.3
NVDPending
Apr 17, 2025 CVE-2025-1525
Ultimate Dashboard: Cross-site scripting
Ultimate Dashboard is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE3.5
NVDPending
Apr 17, 2025 CVE-2025-1524
Ultimate Dashboard: Cross-site scripting
Ultimate Dashboard is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE3.5
NVDPending
Apr 17, 2025 CVE-2025-1523
Ultimate Dashboard: Cross-site scripting
Ultimate Dashboard is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE3.5
NVDPending
Mar 26, 2025 CVE-2025-2276
Ultimate Dashboard – Custom WordPress Dashboard: A security weakness
Ultimate Dashboard – Custom WordPress Dashboard is affected by a security weakness. Exploitation requires at least subscriber-level access. The resulting impact depends on how the affected component exposes the vulnerable operation.
See mitigation notes
CVE4.3
NVDPending
Jun 04, 2024 CVE-2023-49822
Ultimate Dashboard: A security weakness
Ultimate Dashboard is affected by a security weakness. Exposure depends on how the affected operation is made reachable by the site. The resulting impact depends on how the affected component exposes the vulnerable operation.
See mitigation notes
CVE3.7
NVDPending
Dec 21, 2023 CVE-2023-50828
Ultimate Dashboard – Custom WordPress Dashboard: Cross-site scripting
Ultimate Dashboard – Custom WordPress Dashboard is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE5.9
NVD4.8
Nov 22, 2023 CVE-2023-4726
Ultimate Dashboard: Cross-site scripting
Ultimate Dashboard is affected by cross-site scripting. Exploitation requires an authenticated WordPress account. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE4.4
NVD4.8
Jun 19, 2023 CVE-2023-2812
Ultimate Dashboard: Cross-site scripting
Ultimate Dashboard is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE4.8
NVD4.8