CVE-2026-3140: Ultimate Dashboard <= 3.8.14 - Cross-Site Request Forgery to Module Activation/Deactivation
The Ultimate Dashboard plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 3.8.14. This is due to a flawed nonce validation conditional in the 'handlemoduleactions' function. This makes it possible for unauthenticated attackers to toggle plugin modules on or off via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-3140?
CVE-2026-3140 has a medium severity rating due to the risk of unauthorized module activation or deactivation.
How do I fix CVE-2026-3140?
To fix CVE-2026-3140, update the Ultimate Dashboard plugin to version 3.8.15 or higher.
What is affected by CVE-2026-3140?
CVE-2026-3140 affects the Ultimate Dashboard plugin for WordPress versions up to and including 3.8.14.
What is Cross-Site Request Forgery in the context of CVE-2026-3140?
In the context of CVE-2026-3140, Cross-Site Request Forgery allows attackers to perform unauthorized actions on behalf of an authenticated user.
What version of Ultimate Dashboard should I use after CVE-2026-3140?
After CVE-2026-3140, users should upgrade to Ultimate Dashboard version 3.8.15 or later to avoid the vulnerability.