{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","feed_url":"https://feed.craftedsignal.io/vendors/ho3einie/feed.json","home_page_url":"https://feed.craftedsignal.io/","items":[{"_cs_actors":[],"_cs_cpes":[],"_cs_cves":[{"cvss":7.3,"id":"CVE-2026-6079"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["Material Dashboard (1.4.10)"],"_cs_severities":["high"],"_cs_tags":["wordpress","vulnerability","cve"],"_cs_type":"advisory","_cs_vendors":["ho3einie"],"content_html":"\u003cp\u003eThe Material Dashboard plugin for WordPress (all versions up to and including 1.4.10) is vulnerable to unauthorized access and modification of data due to missing capability checks on the amd_ajax_target_task_manager() function. This flaw allows unauthenticated remote attackers to interact with the plugin's task management interface via the public_amd_ajax_handler AJAX action. Successful exploitation enables an attacker to enumerate all scheduled tasks, potentially exposing sensitive information or PII, execute arbitrary tasks, or delete tasks within the WordPress environment. This vulnerability stems from a lack of proper authorization validation before performing administrative actions, effectively granting unauthenticated users the ability to manipulate internal task scheduling.\u003c/p\u003e\n\u003ch2 id=\"attack-chain\"\u003eAttack Chain\u003c/h2\u003e\n\u003col\u003e\n\u003cli\u003eAttacker performs reconnaissance on the target WordPress site to confirm the presence of the Material Dashboard plugin.\u003c/li\u003e\n\u003cli\u003eAttacker crafts an HTTP POST request targeting the WordPress admin-ajax.php endpoint.\u003c/li\u003e\n\u003cli\u003eAttacker specifies the 'public_amd_ajax_handler' action within the request parameters.\u003c/li\u003e\n\u003cli\u003eAttacker includes specific parameters to target the vulnerable amd_ajax_target_task_manager() function.\u003c/li\u003e\n\u003cli\u003eThe plugin fails to verify the user's authorization/capabilities due to the missing check.\u003c/li\u003e\n\u003cli\u003eThe plugin processes the request, allowing the attacker to list, trigger, or delete scheduled tasks.\u003c/li\u003e\n\u003cli\u003eAttacker achieves the final objective of unauthorized data modification or information disclosure via the manipulated tasks.\u003c/li\u003e\n\u003c/ol\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation of this vulnerability leads to unauthorized administrative control over plugin tasks. This includes potential information disclosure of PII contained in scheduled tasks, disruption of site functionality by deleting tasks, and unauthorized execution of tasks, which could be leveraged to further compromise the WordPress instance depending on the specific tasks configured.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cp\u003ePrioritize patching the Material Dashboard plugin immediately to version 1.4.11 or higher where authorization checks have been implemented. Use the web server logs to identify requests containing the 'public_amd_ajax_handler' action parameter to determine if this endpoint has been probed by unauthorized sources. If patching is not immediately feasible, restrict access to the WordPress admin-ajax.php endpoint at the web application firewall (WAF) layer or disable the plugin to mitigate the risk of unauthorized task manipulation.\u003c/p\u003e\n","date_modified":"2026-08-05T09:16:16Z","date_published":"2026-08-05T09:16:16Z","id":"https://feed.craftedsignal.io/briefs/2026-08-material-dashboard-wp/","summary":"The Material Dashboard plugin for WordPress contains a missing authorization vulnerability (CVE-2026-6079) allowing unauthenticated attackers to enumerate, execute, or delete scheduled tasks.","title":"Unauthenticated Authorization Bypass in Material Dashboard WordPress Plugin","url":"https://feed.craftedsignal.io/briefs/2026-08-material-dashboard-wp/"}],"language":"en","title":"CraftedSignal Threat Feed - Ho3einie","version":"https://jsonfeed.org/version/1.1"}