CVE-2026-18432 (matched: wordpress)

  • Monday, 17th August, 2026
  • 10:07am

A security flaw has been identified in the Frontend Admin by DynamiApps plugin for WordPress, impacting all versions up to and including 3.29.9. This vulnerability allows attackers to escalate their account privileges to full administrator level, which gives them unrestricted control over your WordPress site, its content, and all user accounts. The flaw can be exploited in two ways: if you have a public-facing user form configured with this plugin, attackers do not need any account access to your site to carry out the attack. If you do not have a public form set up, an attacker only needs a basic, low-level subscriber account on your site to exploit the vulnerability. Once an attacker gains administrator access, they can change the password and email address of your site's primary admin account, locking you out and taking full control of your website.

Source: NVD (National Vulnerability Database) — https://nvd.nist.gov/vuln/detail/CVE-2026-18432

« Back