CVE-2026-3140
Ultimate Dashboard – Custom WordPress Dashboard
Minimum safe version
3.8.15
Update to 3.8.15 or later to address 11 fixable vulnerabilities
Ultimate Dashboard <= 3.8.5 - Authenticated (Administrator+) Stored Cross-Site Scripting
Ultimate Dashboard <= 3.8.5 - Authenticated (Administrator+) Stored Cross-Site Scripting
Ultimate Dashboard <= 3.8.5 - Authenticated (Administrator+) Stored Cross-Site Scripting
WordPress Ultimate Dashboard Plugin <= 3.8.7 is vulnerable to Broken Access Control
WordPress Ultimate Dashboard Plugin <= 3.7.11 is vulnerable to Cross Site Scripting (XSS)
CVE-2023-49822
CVE-2023-4726
CVE-2023-2812
WordPress Ultimate Dashboard Plugin < 3.7.6 is vulnerable to Cross Site Scripting (XSS)
Ultimate Dashboard <= 3.7.5 - Authenticated(Administrator+) Stored Cross-Site Scripting via plugin settings