There is a security vulnerability in the Frontend Admin by DynamiApps plugin for WordPress, impacting all versions up to and including 3.29.9. This is a privilege escalation flaw, meaning it lets unauthorized users gain full administrator-level access to your WordPress site.
The flaw occurs because the plugin skips a key security check that normally blocks users from editing other people’s account details under specific conditions. If your site has a public-facing user form set up with this plugin, even a visitor who is not logged into your site at all can exploit this vulnerability. If you do not have a public user form configured, only a user with a basic subscriber account (the lowest default access level for WordPress users) would be able to trigger the flaw.
If an attacker successfully exploits this issue, they can take over your site’s main administrator account by changing its password or email address, giving them full control over all your site’s content, settings, and data.
Source: NVD (National Vulnerability Database) — https://nvd.nist.gov/vuln/detail/CVE-2026-18432