
CVE-2026-3140 The Ultimate Dashboard plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 3.8.14. This is due to a flawed nonce vali… https://www.cve.org/CVERecord?id=CVE-2026-3140
Post summary
The text discloses a CSRF vulnerability (CVE‑2026‑3140) in Ultimate Dashboard for WordPress up to version 3.8.14, noting a flawed nonce check but offering no exploitable code, active attack evidence, or patch information.

