CVE-2026-18432 (matched: wordpress)

  • Tuesday, 18th August, 2026
  • 10:06am

A security vulnerability has been found in the "Frontend Admin by DynamiApps" plugin for WordPress, which affects all versions of the plugin up to and including 3.29.9. This flaw allows unauthorized users to gain full administrator access to your WordPress site under specific conditions. If an attacker gains this level of access, they can take full control of your site: they may change your site's content, steal private data from your visitors or business records, or make harmful changes that break your site's functionality.

For this vulnerability to be exploited, your site must be using this specific plugin, and one of two conditions must be met: either you have a public-facing user form enabled on your site's front end, or an attacker has a basic low-level subscriber account on your site. If these conditions are true, an attacker can exploit the flaw to change the password or email address linked to your site's primary administrator account. This lets them log in as an admin and take full control of your site without your knowledge.

Source: NVD (National Vulnerability Database) — https://nvd.nist.gov/vuln/detail/CVE-2026-18432

« Back