CVE-2026-18432 (matched: wordpress)

  • Tuesday, 18th August, 2026
  • 16:05pm

A security flaw has been found in the Frontend Admin by DynamiApps plugin for WordPress, affecting all versions up to and including 3.29.9. This is a privilege escalation vulnerability, meaning it lets unauthorized people gain higher-level access to your WordPress site than they are supposed to have. Attackers can exploit this issue without being logged into your site if you have a public-facing user form set up using this plugin. If you do not have a public user form configured, an attacker only needs a basic low-level subscriber account on your site to carry out the attack. If successful, the attacker can gain full administrator access to your site, allowing them to change the password or email address of your main admin account to take over complete control of your website.

Source: NVD (National Vulnerability Database) — https://nvd.nist.gov/vuln/detail/CVE-2026-18432

« Back