Medium 6.5
2025-06-06< 2.2.9
CVE-2025-49310
Minimum safe version
2.2.9
Update to 2.2.9 or later to address 8 fixable vulnerabilities
CVE-2025-49310
Frontend Dashboard 1.0 - 2.2.7 - Missing Authorization to Authenticated (Subscriber+) Privilege Escalation via fed_admin_setting_form_function Function
Frontend Dashboard 1.5.10 - 2.2.7 - Missing Authorization to Authenticated (Subscriber+) Account Takeover/Privilege Escalation via ajax_request Function
Frontend Dashboard 1.0 - 2.2.6 - Missing Authorization to Unauthenticated Privilege Escalation via fed_wp_ajax_fed_login_form_post Function
CVE-2025-46248
CVE-2024-8268
CVE-2024-32726
CVE-2024-29775