Skip to content
Security

Straight answers about FleekDash security

What we fix, what we publish, and what you should do. No burying bad news. Every confirmed vulnerability gets a public advisory with affected versions and the release that fixes it.

All known vulnerabilities are patched

Latest stable release, served by the FleekDash update server — update from Dashboard → Updates in WordPress.

v2.6.7.1

Security advisories

Confirmed vulnerabilities and the releases that fixed them.

CVE-2026-14356

Missing authorization in the registration REST endpoint

High · CVSS 8.8
Published
July 30, 2026
Severity
High (CVSS 8.8)
Type
CWE-862 · Missing authorization
Affected versions
FleekDash V2 up to 2.6.2.2
Fixed in
2.6.2.5 and later
Reported by
maru finder, via Wordfence

What happened

The /wp-json/fleekdash/v1/register endpoint did not verify that the caller was allowed to create or modify accounts. A logged-in user with a low-privilege role (or anyone able to register) could change the email and password of any other account, including administrators.

What to do

  1. Open your WordPress admin and go to Dashboard → Updates (or Plugins).
  2. Update FleekDash to the latest stable version. The fix shipped in 2.6.2.5; every release after it is patched.
  3. If you were running 2.6.2.2 or older with open registration enabled, review your user list for accounts you don't recognize and reset admin passwords as a precaution.

Found something? Tell us first

Contact us

Email hey@fleekdash.com or use the contact form with steps to reproduce. We investigate every report, ship fixes through the normal WordPress update channel, and credit researchers who disclose responsibly.

Please give us reasonable time to patch before publishing details. That window is what keeps site owners safe.

The plugin itself does not collect, store, or transmit your site's content. The only external calls it makes are license and update checks. Details live in our privacy policy.

Common questions

  • Is my site affected by CVE-2026-14356?

    Only sites running FleekDash V2 version 2.6.2.2 or older are affected. The vulnerability was fixed in version 2.6.2.5. Update FleekDash from your WordPress dashboard to stay protected.

  • How do I report a security vulnerability?

    Email hey@fleekdash.com or use the contact form with details and steps to reproduce. Please give us time to ship a fix before publishing anything publicly.

  • Does FleekDash send data from my site to external servers?

    No. The plugin runs entirely inside your WordPress installation and does not collect, store, or transmit your site content. The only external calls are license and update checks.

Give your projects an instant wow factor today_

14 Days Money Back Guarantee
14-day money back guarantee | No questions asked
30% DISCOUNT

Agency LTD plan closes in

Agency LTD plan closes in 3 days