HomeWordPress vulnerabilitiesFrontend Admin by DynamiApps
Frontend Admin by DynamiApps vulnerabilities
Frontend Admin by DynamiApps has 22 known vulnerabilities in this database. The most recent published record is dated 6 Sep 2026.
- Known vulnerabilities
- 22
- Active installs
- 8,000+
- Latest version
- 3.29.13
- Last updated
- 25 Aug 2026
- Most recent
- 6 Sep 2026
Find it in your WordPress dashboard under Plugins. Severity is based on the CVSS score published with the CVE where one is available.
| Vulnerability | Severity | Affected | Fix | Published |
|---|---|---|---|---|
| Authentication bypass CVE-2026-75816 | Critical 9.8 | Up to 3.29.12 | Fixed in a later version (latest 3.29.13) | 6 Sep 2026 |
| Arbitrary file deletion CVE-2026-81347 | Medium 5.9 | Before 3.29.13 | Fixed in 3.29.13 | 4 Sep 2026 |
| Remote code execution CVE-2026-19952 | High 7.5 | Up to 3.29.12 | Fixed in a later version (latest 3.29.13) | 1 Sep 2026 |
| Cross-site scripting (XSS) CVE-2026-12747 | Medium 6.4 | Up to 3.29.11 | Fixed in a later version (latest 3.29.13) | 1 Sep 2026 |
| Broken access control CVE-2026-81346 | Medium 4.3 | Before 3.29.11 | Fixed in 3.29.11 | 29 Aug 2026 |
| Privilege escalation CVE-2026-18432 | Critical 9.8 | Up to 3.29.9 | Fixed in a later version (latest 3.29.13) | 16 Aug 2026 |
| Authentication bypass CVE-2026-15606 | High 8.8 | Up to 3.29.9 | Fixed in a later version (latest 3.29.13) | 11 Aug 2026 |
| Cross-site scripting (XSS) CVE-2026-13609 | High 8.8 | Before 3.29.9 | Fixed in 3.29.9 | 31 Jul 2026 |
| Broken access control CVE-2026-11867 | Medium 6.5 | Before 3.29.7 | Fixed in 3.29.7 | 30 Jul 2026 |
| SQL injection CVE-2026-10039 | Medium 4.9 | Up to 3.28.28 | Fixed in a later version (latest 3.29.13) | 29 May 2026 |
| Privilege escalation CVE-2026-6226 | High 8.8 | Up to 3.29.2 | Fixed in a later version (latest 3.29.13) | 28 May 2026 |
| Authentication bypass CVE-2026-7802 | High 8.8 | Up to 3.29.2 | Fixed in a later version (latest 3.29.13) | 28 May 2026 |
| Privilege escalation CVE-2026-6228 | High 8.8 | Up to 3.28.36 | Fixed in a later version (latest 3.29.13) | 15 May 2026 |
| Remote code execution CVE-2026-3328 | High 7.2 | Up to 3.28.31 | Fixed in a later version (latest 3.29.13) | 26 Mar 2026 |
| Broken access control CVE-2025-14741 | Critical 9.1 | Up to 3.28.25 | Fixed in a later version (latest 3.29.13) | 9 Jan 2026 |
| Cross-site scripting (XSS) CVE-2025-14937 | High 7.2 | Up to 3.28.23 | Fixed in a later version (latest 3.29.13) | 9 Jan 2026 |
| Privilege escalation CVE-2025-14736 | Critical 9.8 | Up to 3.28.29 | Fixed in a later version (latest 3.29.13) | 9 Jan 2026 |
| Broken access control CVE-2025-13342 | Critical 9.8 | Up to 3.28.20 | Fixed in a later version (latest 3.29.13) | 3 Dec 2025 |
| SQL injection CVE-2024-11722 | Medium 5.9 | Before 3.25.2 | Fixed in 3.25.2 | 21 Dec 2024 |
| Privilege escalation CVE-2024-11721 | High 8.1 | Before 3.25.1 | Fixed in 3.25.1 | 14 Dec 2024 |
| Cross-site scripting (XSS) CVE-2024-11720 | High 7.2 | Before 3.25.1 | Fixed in 3.25.1 | 14 Dec 2024 |
| Privilege escalation CVE-2024-3729 | Critical 9.8 | Before 3.19.5 | Fixed in 3.19.5 | 2 May 2024 |
Read the published descriptions
- CVE-2026-75816, 6 Sep 2026
- The Frontend Admin by DynamiApps plugin for WordPress is vulnerable to Authentication Bypass to Account Takeover in all versions up to, and including, 3.29.12. This is due to the pre_update_value function lacking any capability or ownership check, and ActionPost::conditions_logic() short-circuiting its current_user_can('edit_post') authorization gate whenever the post ID is non-numeric - such as the string user_1 - allowing unauthenticated form submissions to be routed to arbitrary user records without restriction. This makes it possible for unauthenticated attackers to overwrite any user's registered email address, including an administrator's, and then leverage WordPress's native password-reset flow to fully take over the targeted account. CVE record
- CVE-2026-81347, 4 Sep 2026
- The Frontend Admin by DynamiApps WordPress plugin before 3.29.13 does not properly validate a user-controllable directory path before deleting files within it, allowing unauthenticated attackers to delete index.php and .htaccess files outside the intended directory, including the WordPress root, which can render the site inoperable. Successful exploitation requires a non-default form configuration. CVE record
- CVE-2026-19952, 1 Sep 2026
- The Frontend Admin by DynamiApps plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the move_folders function in all versions up to, and including, 3.29.12. This makes it possible for unauthenticated attackers to delete arbitrary files on the server, which can easily lead to remote code execution when the right file is deleted (such as wp-config.php). This is exploitable without authentication when a form is configured with public visibility (who_can_see='all'), as the required nonce is publicly obtainable from the rendered form. CVE record
- CVE-2026-12747, 1 Sep 2026
- The Frontend Admin by DynamiApps plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'tag' Shortcode Attribute in all versions up to, and including, 3.29.11 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. CVE record
- CVE-2026-81346, 29 Aug 2026
- The Frontend Admin by DynamiApps WordPress plugin before 3.29.11 does not perform a capability check on one of its AJAX actions, allowing any authenticated user, such as a subscriber, to delete arbitrary membership plans. CVE record
- CVE-2026-18432, 16 Aug 2026
- The Frontend Admin by DynamiApps plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 3.29.9. The vulnerability exists because `ActionUser::conditions_logic()` gates the `current_user_can('edit_user', $user_id)` authorization check behind an `is_numeric()` test, causing the check to be skipped entirely when `$user_id` is a non-numeric string - a condition that can be induced by passing a crafted value such as `1one` through the unvalidated `item_id` parameter of the unauthenticated `wp_ajax_nopriv_frontend_admin/forms/change_form` AJAX endpoint. This makes it possible for attackers to escalate privileges to administrator by obtaining a server-signed `_acf_objects` payload carrying the non-numeric user ID, which WordPress subsequently coerces to integer 1 (the default administrator), allowing the attacker to overwrite that account's password or email address. Exploitation by unauthenticated users requires a public-facing frontend user form to be configured; in all other cases a subscriber-level account is sufficient. CVE record
- CVE-2026-15606, 11 Aug 2026
- The Frontend Admin by DynamiApps plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 3.29.9. This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it possible for authenticated attackers, with subscriber-level and above permissions, to reset the password of any user on the site, including administrators, leading to full account takeover and complete site compromise. Exploitation requires the attacker to hold a valid encrypted Current-User token obtained by accessing any Edit User form they are legitimately authorized to submit, which they then use as a known-plaintext base for the CBC bit-flipping forgery. CVE record
- CVE-2026-13609, 31 Jul 2026
- The Frontend Admin by DynamiApps WordPress plugin before 3.29.9 decodes HTML entities in a submitted form field value after sanitizing it, which restores HTML tags that the sanitizer had neutralized. A double-encoded payload submitted by an unauthenticated visitor is therefore stored as a live tag and later output without escaping on the Frontend Admin by DynamiApps WordPress plugin before 3.29.9's front-end display surfaces, resulting in stored cross-site scripting that executes in the browser of any user, including an administrator, who views a page displaying the submitted value. CVE record
- CVE-2026-11867, 30 Jul 2026
- The Frontend Admin by DynamiApps WordPress plugin before 3.29.7 does not perform capability checks on its taxonomy term creation, modification, and deletion operations, allowing authenticated users with low privileges (such as Subscribers) to create, rename, and delete arbitrary taxonomy terms. CVE record
- CVE-2026-10039, 29 May 2026
- The Frontend Admin by DynamiApps plugin for WordPress is vulnerable to generic SQL Injection via the 'order' parameter in all versions up to, and including, 3.28.28 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticated attackers, with administrator-level access and above, to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database. Exploitation requires that the attacker also supply a valid 'orderby' parameter in the same request, as this is necessary to reach the vulnerable code path that processes and concatenates the 'order' value into the SQL query. CVE record
- CVE-2026-6226, 28 May 2026
- The Frontend Admin by DynamiApps plugin for WordPress is vulnerable to unauthenticated privilege escalation in versions up to and including 3.29.2. This is due to insecure form submission handling that accepts arbitrary form definitions from user input instead of securely loading them from the backend. When $_POST['_acf_form'] is an array (rather than a form ID), the validate_form() function bypasses database lookup and directly processes the attacker-controlled structure. The create_record() function preserves attacker-supplied record data if present, and the user action's run() function falls back to attacker-controlled field definitions from $form['fields'] when legitimate fields cannot be found. The role field's pre_update_value() validation reads $field['role_options'] from this attacker-controlled definition, allowing an attacker to specify ['administrator'] as an allowed role and bypass the security check. This makes it possible for unauthenticated attackers to create administrator accounts by injecting a custom form configuration with a spoofed role field. CVE record
- CVE-2026-7802, 28 May 2026
- The Frontend Admin by DynamiApps plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 3.29.2. This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it possible for authenticated attackers, with subscriber-level access and above, to overwrite an administrator's user_pass, user_email, first_name, last_name, and other profile fields by supplying an arbitrary ?user_id= value, enabling full administrator account takeover via direct password replacement or email-redirect password reset. Exploitation requires the targeted Edit-User form to have its 'Roles' configuration setting left empty; when a non-empty roles list is configured, load_data() sets the user ID to 'none' for users whose roles fall outside the allowed list, preventing administrators from being targeted through that form. CVE record
- CVE-2026-6228, 15 May 2026
- The Frontend Admin by DynamiApps plugin for WordPress is vulnerable to Privilege Escalation in versions up to and including 3.28.36. This is due to insufficient authorization checks in the role field update mechanism combined with overly permissive capabilities for the admin_form post type. The admin_form custom post type uses 'capability_type' => 'page', which grants editors the ability to create and edit forms. When an editor creates an edit_user form, they can manipulate the form configuration to include 'administrator' in the role_options array by directly submitting POST data to wp-admin/post.php, bypassing the UI restrictions in feadmin_get_user_roles(). When the form is subsequently submitted, the pre_update_value() function in class-role.php only validates that the submitted role exists in the form's role_options array (lines 107-110), but fails to verify that the current user has permission to assign that specific role. This makes it possible for unauthenticated attackers to first register as editors (via a public new_user form), then create an edit_user form with administrator in the allowed roles, and finally use that form to escalate their own privileges to administrator. CVE record
- CVE-2026-3328, 26 Mar 2026
- The Frontend Admin by DynamiApps plugin for WordPress is vulnerable to PHP Object Injection via deserialization of the 'post_content' of admin_form posts in all versions up to, and including, 3.28.31. This is due to the use of WordPress's `maybe_unserialize()` function without class restrictions on user-controllable content stored in admin_form post content. This makes it possible for authenticated attackers, with Editor-level access and above, to inject a PHP Object. The additional presence of a POP chain allows attackers to achieve remote code execution. CVE record
- CVE-2025-14741, 9 Jan 2026
- The Frontend Admin by DynamiApps plugin for WordPress is vulnerable to missing authorization to unauthorized data modification and deletion due to a missing capability check on the 'delete_object' function in all versions up to, and including, 3.28.25. This makes it possible for unauthenticated attackers to delete arbitrary posts, pages, products, taxonomy terms, and user accounts. CVE record
- CVE-2025-14937, 9 Jan 2026
- The Frontend Admin by DynamiApps plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'acff' parameter in the 'frontend_admin/forms/update_field' AJAX action in all versions up to, and including, 3.28.23 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. CVE record
- CVE-2025-14736, 9 Jan 2026
- The Frontend Admin by DynamiApps plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 3.28.29. This is due to insufficient validation of user-supplied role values in the 'validate_value', 'pre_update_value', and 'get_fields_display' functions. This makes it possible for unauthenticated attackers to register as administrators and gain complete control of the site, granted they can access a user registration form containing a Role field. CVE record
- CVE-2025-13342, 3 Dec 2025
- The Frontend Admin by DynamiApps plugin for WordPress is vulnerable to unauthorized modification of arbitrary WordPress options in all versions up to, and including, 3.28.20. This is due to insufficient capability checks and input validation in the ActionOptions::run() save handler. This makes it possible for unauthenticated attackers to modify critical WordPress options such as users_can_register, default_role, and admin_email via submitting crafted form data to public frontend forms. CVE record
- CVE-2024-11722, 21 Dec 2024
- The Frontend Admin by DynamiApps plugin for WordPress is vulnerable to SQL Injection via the 'orderby' parameter in all versions up to, and including, 3.25.1 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for unauthenticated attackers to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database. This requires an unauthenticated user to have been given permission to view form submissions, and the form submission shortcode be added to a page. CVE record
- CVE-2024-11721, 14 Dec 2024
- The Frontend Admin by DynamiApps plugin for WordPress is vulnerable to privilege escalation in all versions up to, and including, 3.24.5. This is due to insufficient controls on the user role select field when utilizing the 'Role' field in a form. This makes it possible for unauthenticated attackers to create new administrative user accounts, even when the administrative user role has not been provided as an option to the user, granted that unauthenticated users have been provided access to the form. CVE record
- CVE-2024-11720, 14 Dec 2024
- The Frontend Admin by DynamiApps plugin for WordPress is vulnerable to Stored Cross-Site Scripting via submission forms in all versions up to, and including, 3.24.5 due to insufficient input sanitization and output escaping on the new Taxonomy form. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. This is only exploitable when lower-level users have been granted access to submit specific forms, which is disabled by default. CVE record
- CVE-2024-3729, 2 May 2024
- The Frontend Admin by DynamiApps plugin for WordPress is vulnerable to improper missing encryption exception handling on the 'fea_encrypt' function in all versions up to, and including, 3.19.4. This makes it possible for unauthenticated attackers to manipulate the user processing forms, which can be used to add and edit administrator user for privilege escalation, or to automatically log in users for authentication bypass, or manipulate the post processing form that can be used to inject arbitrary web scripts. This can only be exploited if the 'openssl' php extension is not loaded on the server. CVE record
What to do if you run Frontend Admin by DynamiApps
If you run Frontend Admin by DynamiApps, open WordPress and check the installed version in Plugins. Compare it with the affected versions in the vulnerability record. If a fixed version is available, take a current backup and update to that version or the latest supported release.
If no fixed version exists, consider disabling and removing the plugin or replacing it with a maintained alternative. After dealing with the affected software, check administrator users, unexpected file changes, redirects, unfamiliar pages and security logs for signs that the site may already have been altered.
Email me about new Frontend Admin by DynamiApps vulnerabilities
Free. We email you when a new vulnerability is published for Frontend Admin by DynamiApps, usually within minutes. Confirm by email; unsubscribe any time.
Focus on your business. We’ll take care of your website.
From everyday updates to ongoing care, we keep your website working.