CSIRTS // UNIFIED SECURITY ADVISORY FEEDSYS ● ONLINE · POWERED BY INTELFUSIONS.COM

CVE-2026-6079

highCVSS 7.3covered by 1 sourcefirst seen 2026-08-05
The Material Dashboard plugin for WordPress is vulnerable to unauthorized access and modification of data due to missing capability checks on the amd_ajax_target_task_manager() function in all versions up to, and including, 1.4.10. This makes it possible for unauthenticated attackers to enumerate all scheduled tasks (potentially exposing PII), execute arbitrary tasks, and delete any task via the public_amd_ajax_handler AJAX action.

⚡ Watch CVE-2026-6079

Get an email if CVE-2026-6079 is added to CISA KEV, gains public exploit code, or a new advisory cites it — max one per day, one-click unsubscribe.

Exploitation outlook

Advisory coverage (1)

External references

NVD record for CVE-2026-6079

CVE.org record

Embed the live status

CVE-2026-6079 live status badge — this badge updates automatically when the KEV or exploit status changes. How to embed it →

[![CVE-2026-6079 status](https://www.csirts.com/badge/CVE-2026-6079)](https://www.csirts.com/cve/CVE-2026-6079)