CVE-2026-81347
- EPSS 0.23%
- Veröffentlicht 04.09.2026 06:00:04
- Zuletzt bearbeitet 08.09.2026 19:15:18
The Frontend Admin by DynamiApps WordPress plugin before 3.29.13 does not properly validate a user-controllable directory path before deleting files within it, allowing unauthenticated attackers to delete index.php and .htaccess files outside the int...
CVE-2026-19952
- EPSS 0.78%
- Veröffentlicht 01.09.2026 04:27:50
- Zuletzt bearbeitet 01.09.2026 20:47:54
The Frontend Admin by DynamiApps plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the move_folders function in all versions up to, and including, 3.29.12. This makes it possible for unauthentic...
CVE-2026-81346
- EPSS 0.15%
- Veröffentlicht 29.08.2026 06:18:02
- Zuletzt bearbeitet 31.08.2026 20:14:36
The Frontend Admin by DynamiApps WordPress plugin before 3.29.11 does not perform a capability check on one of its AJAX actions, allowing any authenticated user, such as a subscriber, to delete arbitrary membership plans.
CVE-2026-66638
- EPSS 0.21%
- Veröffentlicht 18.08.2026 13:59:44
- Zuletzt bearbeitet 20.08.2026 12:48:31
Contributor Cross Site Scripting (XSS) in Frontend Admin by DynamiApps <= 3.29.10 versions.
CVE-2026-18432
- EPSS 0.45%
- Veröffentlicht 16.08.2026 04:24:49
- Zuletzt bearbeitet 20.08.2026 12:48:10
The Frontend Admin by DynamiApps plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 3.29.9. The vulnerability exists because `ActionUser::conditions_logic()` gates the `current_user_can('edit_user', $user...
CVE-2026-66470
- EPSS 0.31%
- Veröffentlicht 06.08.2026 14:27:53
- Zuletzt bearbeitet 12.08.2026 20:58:37
Subscriber Broken Access Control in Frontend Admin by DynamiApps <= 3.29.10 versions.
CVE-2026-13609
- EPSS 0.16%
- Veröffentlicht 31.07.2026 06:00:11
- Zuletzt bearbeitet 26.08.2026 16:31:36
The Frontend Admin by DynamiApps WordPress plugin before 3.29.9 decodes HTML entities in a submitted form field value after sanitizing it, which restores HTML tags that the sanitizer had neutralized. A double-encoded payload submitted by an unauthent...
CVE-2026-11867
- EPSS 0.14%
- Veröffentlicht 30.07.2026 06:24:58
- Zuletzt bearbeitet 30.07.2026 16:45:00
The Frontend Admin by DynamiApps WordPress plugin before 3.29.7 does not perform capability checks on its taxonomy term creation, modification, and deletion operations, allowing authenticated users with low privileges (such as Subscribers) to create,...
CVE-2026-7802
- EPSS 0.42%
- Veröffentlicht 28.05.2026 03:27:28
- Zuletzt bearbeitet 28.05.2026 13:45:25
The Frontend Admin by DynamiApps plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 3.29.2. This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it p...
CVE-2026-6228
- EPSS 0.44%
- Veröffentlicht 15.05.2026 07:46:36
- Zuletzt bearbeitet 15.05.2026 14:09:15
The Frontend Admin by DynamiApps plugin for WordPress is vulnerable to Privilege Escalation in versions up to and including 3.28.36. This is due to insufficient authorization checks in the role field update mechanism combined with overly permissive c...