CVE-2026-66638
- EPSS 0.21%
- Veröffentlicht 18.08.2026 13:59:44
- Zuletzt bearbeitet 20.08.2026 12:48:31
Contributor Cross Site Scripting (XSS) in Frontend Admin by DynamiApps <= 3.29.10 versions.
CVE-2026-18432
- EPSS 0.45%
- Veröffentlicht 16.08.2026 04:24:49
- Zuletzt bearbeitet 20.08.2026 12:48:10
The Frontend Admin by DynamiApps plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 3.29.9. The vulnerability exists because `ActionUser::conditions_logic()` gates the `current_user_can('edit_user', $user...
CVE-2026-66470
- EPSS 0.31%
- Veröffentlicht 06.08.2026 14:27:53
- Zuletzt bearbeitet 12.08.2026 20:58:37
Subscriber Broken Access Control in Frontend Admin by DynamiApps <= 3.29.10 versions.
CVE-2026-13609
- EPSS 0.16%
- Veröffentlicht 31.07.2026 06:00:11
- Zuletzt bearbeitet 31.07.2026 17:16:32
The Frontend Admin by DynamiApps WordPress plugin before 3.29.9 decodes HTML entities in a submitted form field value after sanitizing it, which restores HTML tags that the sanitizer had neutralized. A double-encoded payload submitted by an unauthent...
CVE-2026-11867
- EPSS 0.14%
- Veröffentlicht 30.07.2026 06:24:58
- Zuletzt bearbeitet 30.07.2026 16:45:00
The Frontend Admin by DynamiApps WordPress plugin before 3.29.7 does not perform capability checks on its taxonomy term creation, modification, and deletion operations, allowing authenticated users with low privileges (such as Subscribers) to create,...
CVE-2026-7802
- EPSS 0.42%
- Veröffentlicht 28.05.2026 03:27:28
- Zuletzt bearbeitet 28.05.2026 13:45:25
The Frontend Admin by DynamiApps plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 3.29.2. This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it p...
CVE-2026-6228
- EPSS 0.44%
- Veröffentlicht 15.05.2026 07:46:36
- Zuletzt bearbeitet 15.05.2026 14:09:15
The Frontend Admin by DynamiApps plugin for WordPress is vulnerable to Privilege Escalation in versions up to and including 3.28.36. This is due to insufficient authorization checks in the role field update mechanism combined with overly permissive c...
CVE-2025-14937
- EPSS 0.27%
- Veröffentlicht 09.01.2026 07:22:10
- Zuletzt bearbeitet 15.04.2026 00:35:42
The Frontend Admin by DynamiApps plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'acff' parameter in the 'frontend_admin/forms/update_field' AJAX action in all versions up to, and including, 3.28.23 due to insufficient input...
CVE-2025-49267
- EPSS 0.27%
- Veröffentlicht 14.08.2025 10:34:10
- Zuletzt bearbeitet 23.04.2026 15:31:21
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Shabti Kaplan Frontend Admin by DynamiApps acf-frontend-form-element allows Blind SQL Injection.This issue affects Frontend Admin by DynamiApps: fro...
CVE-2025-49303
- EPSS 0.41%
- Veröffentlicht 04.07.2025 11:18:00
- Zuletzt bearbeitet 23.04.2026 15:31:25
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Shabti Kaplan Frontend Admin by DynamiApps acf-frontend-form-element allows Path Traversal.This issue affects Frontend Admin by DynamiApps: from n/a throu...