CVE-2026-18432 (matched: wordpress)

  • Monday, 17th August, 2026
  • 22:04pm

A security vulnerability has been found in the Frontend Admin by DynamiApps plugin for WordPress, affecting all versions up to and including 3.29.9. This flaw could let unauthorized users gain full administrator access to your WordPress site.

If you have a public-facing user form configured to use this plugin, even people who are not logged into your site at all could exploit this flaw to take control of your site’s main administrator account, by changing its password or associated email address to lock you out. If you do not have a public front-end form set up, an attacker would only need a low-level subscriber account on your site to carry out this attack.

Source: NVD (National Vulnerability Database) — https://nvd.nist.gov/vuln/detail/CVE-2026-18432

« Back