
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-3140 is a Cross-Site Request Forgery (CSRF) vulnerability in the Ultimate Dashboard plugin for WordPress, affecting all versions up to and including 3.8.14. The flaw resides in the handle_module_actions function, where a flawed nonce validation conditional allows unauthenticated attackers to toggle plugin modules on or off by tricking a site administrator into clicking a malicious link. It was published on May 1, 2026, and assigned a CVSS v3.1 base score of 4.3 (Medium) (GitHub Advisory, Wordfence).
The vulnerability is classified as CWE-352 (Cross-Site Request Forgery) and stems from improper nonce validation logic in the handle_module_actions function within modules/feature/class-feature-module.php (line 120). Because the nonce check is conditionally flawed rather than strictly enforced, a crafted HTTP request can bypass the intended authentication gate. Exploitation requires social engineering — the attacker must trick an authenticated administrator into clicking a forged link, at which point the request is processed with the administrator's session privileges (GitHub Advisory, WordPress Trac).
Successful exploitation allows an unauthenticated attacker to toggle Ultimate Dashboard plugin modules on or off without authorization. The primary risk is an integrity impact: attackers could disable security-relevant modules or enable unwanted functionality on the WordPress site. There is no direct confidentiality or availability impact, and the vulnerability does not provide a path to remote code execution on its own (GitHub Advisory, Wordfence).
No public proof-of-concept exploit code has been identified, and there is no evidence of in-the-wild exploitation at this time. The EPSS score is approximately 0.012% (0th percentile), indicating a very low probability of exploitation in the near term. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. Exploitation requires user interaction from a site administrator, which limits opportunistic attack scenarios (GitHub Advisory, Wordfence).
handle_module_actions function that toggles a specific plugin module on or off, exploiting the flawed nonce validation to bypass CSRF protection.<img> tag, hidden form, or direct URL) and deliver it to a site administrator through phishing email, forum post, or other communication channel.handle_module_actions originating from unexpected referrers or with missing/invalid nonce values.Users should update the Ultimate Dashboard plugin to a version newer than 3.8.14, which includes a fix for the flawed nonce validation (patch changeset available at WordPress Trac). As an interim measure, restrict WordPress admin access to trusted users only, monitor admin activity logs for unexpected module state changes, and consider deploying a Web Application Firewall (WAF) with CSRF protection rules. Administrators should also follow general security hygiene by avoiding clicking unsolicited links while logged into the WordPress dashboard (WordPress Trac Changeset, Wordfence).
Wordfence included CVE-2026-3140 in their weekly WordPress vulnerability report for the period of April 27–May 3, 2026, noting the CSRF flaw in the Ultimate Dashboard plugin. No significant independent researcher commentary or broader media coverage has been identified beyond standard vulnerability database aggregation (Wordfence Blog).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."