CVE-2026-18432 (matched: wordpress)

  • Sunday, 16th August, 2026
  • 16:06pm

A security vulnerability has been found in the "Frontend Admin by DynamiApps" plugin for WordPress, affecting all versions up to and including 3.29.9. This is a privilege escalation flaw, which means an unauthorized user could gain full administrator access to your WordPress site, giving them control over all your site’s content, settings, and user accounts.

To exploit this issue, an attacker would either need no login credentials at all if you have a public-facing user form set up with this plugin, or only a basic low-level subscriber account if you do not have that public form enabled. If the exploit is successful, the attacker can change the password or email address for your site’s main administrator account, letting them take full control of your website.

Source: NVD (National Vulnerability Database) — https://nvd.nist.gov/vuln/detail/CVE-2026-18432

« Back