A security vulnerability has been found in the Frontend Admin by DynamiApps plugin for WordPress, a tool many site owners use to manage WordPress features directly from the public part of their website. The flaw affects all versions of the plugin up to and including version 3.29.9.
The vulnerability lets unauthorized users gain full administrator access to your WordPress site. If exploited, an attacker could take over your site's primary admin account, giving them the ability to change your login credentials, access all your private site content and data, and modify your site's core settings.
To carry out this attack, an unapproved user would either need a public-facing user form (such as a sign-up or contact form) configured to work with this plugin on your site, or a basic low-level subscriber account on your WordPress site if you do not have that public form set up.
Source: NVD (National Vulnerability Database) — https://nvd.nist.gov/vuln/detail/CVE-2026-18432