{"id":"CVE-2026-6079","published":"2026-08-05T08:16:40.997","lastModified":"2026-08-05T14:17:11.913","description":"The Material Dashboard plugin for WordPress is vulnerable to unauthorized access and modification of data due to missing capability checks on the amd_ajax_target_task_manager() function in all versions up to, and including, 1.4.10. This makes it possible for unauthenticated attackers to enumerate all scheduled tasks (potentially exposing PII), execute arbitrary tasks, and delete any task via the public_amd_ajax_handler AJAX action.","cvssScore":7.3,"cvssSeverity":"HIGH","cvssVector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L","cwes":["CWE-862"],"vendors":[],"products":[],"references":[{"url":"https://plugins.trac.wordpress.org/browser/material-dashboard/trunk/core/AMDNetwork/AMDNetwork.php#L26","tags":[]},{"url":"https://plugins.trac.wordpress.org/browser/material-dashboard/trunk/core/AMDTasks/AMDTasks.php#L514","tags":[]},{"url":"https://plugins.trac.wordpress.org/changeset?new=3535650%40material-dashboard%2Ftrunk&old=3535649%40material-dashboard%2Ftrunk","tags":[]},{"url":"https://www.wordfence.com/threat-intel/vulnerabilities/id/459b7fef-806c-4f5b-bb31-b7197750e941?source=cve","tags":[]}],"exploitRefs":[],"hasPoc":false,"ai":{"summary":"The flaw allows unauthenticated attackers to modify and access data through missing capability checks in the Material Dashboard plugin for WordPress.","exploitability":"Exploitation is relatively easy as no authentication is required, but attackers need to know the specific task IDs.","blast_radius":"If exploited, this could lead to unauthorized execution of tasks, deletion of critical data, and exposure of sensitive information.","remediation":"Update the Material Dashboard plugin to the latest version immediately or disable the affected functionality.","tags":["auth-bypass","data-exposure","wp-plugin","web"],"model":"qwen2.5:7b-instruct","analyzedAt":"2026-08-11T07:00:45.826Z"}}