CVE-2024-56071 CRITICAL

CVE-2024-56071: WordPress Simple Dashboard plugin <= 2.0 - Privilege Escalation vulnerability

Vendor Mikeleembruggen
Product Simple Dashboard
Weakness CWE-266
Published December 31, 2024
Last update May 11, 2026

CVSS base score

9.8/10
Attack vector Network
Attack complexity Low
Privileges required None
User interaction None
Confidentiality High
Integrity High

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

What the vulnerability does

01Description

Incorrect Privilege Assignment vulnerability in mikeleembruggen Simple Dashboard simple-dashboard allows Privilege Escalation.This issue affects Simple Dashboard: from n/a through <= 2.0.

Explanation of Vulnerability in Simple Terms

02Summary

Simple Dashboard versions 2.0 and earlier contain a critical vulnerability allowing unauthenticated attackers to read sensitive data, modify site content, and disrupt service. The flaw stems from improper privilege enforcement, enabling network-based exploitation without user interaction. All installations should update immediately.

What an attacker can do

03Attacker Capabilities

Read sensitive data, modify content, and disrupt the site without logging in.

Potential impact on your site

04Site Impact

Attackers can access private data, alter pages, and take the dashboard offline without any credentials.

Conditions required to exploit

05Prerequisites

Network access only; no authentication or user interaction required.

Key dates

06Disclosure timeline

December 31, 2024 CVE published
May 11, 2026 Record updated