A security vulnerability has been identified in the Frontend Admin by DynamiApps WordPress plugin, affecting all versions up to and including 3.29.9. This flaw allows attackers to gain full administrator-level access to your website, giving them complete control over your site. They could change your login credentials, access private customer or business data stored on your site, or alter your website’s content, appearance, and core functionality.
This exploit works in two scenarios. If you have a public-facing user form configured on your site using this plugin, attackers do not need any kind of account or login to carry out the attack. If you do not have that public form enabled, attackers would only need a basic low-level subscriber account on your site to exploit the vulnerability.
Source: NVD (National Vulnerability Database) — https://nvd.nist.gov/vuln/detail/CVE-2026-18432