CVE-2026-18432 (matched: wordpress)

  • Sunday, 16th August, 2026
  • 10:07am

A security vulnerability has been found in the Frontend Admin by DynamiApps plugin for WordPress, impacting all versions up to and including 3.29.9. This is a privilege escalation flaw, meaning an unauthorized person could gain full administrator-level access to your WordPress site.

The vulnerability can be exploited in two common scenarios: if you have public-facing user forms set up through this plugin, any visitor to your site (even someone who is not logged in) could use the flaw to gain access. If you do not have public frontend forms enabled, a person with a basic subscriber-level account on your site (the lowest standard tier of user access) could still carry out the attack.

If an attacker successfully exploits this issue, they can take over your site’s primary administrator account by changing its password or registered email address. Once they have administrator access, they can alter your site’s content, access private data stored on your site, or take full control of your website.

Source: NVD (National Vulnerability Database) — https://nvd.nist.gov/vuln/detail/CVE-2026-18432

« Back